Junglewise Threat Intelligence

CVE-2026-50469: Microsoft Windows Projected File System privilege escalation

CVE-2026-50469 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Projected File System, a component that helps manage virtual files and directories. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

A privilege escalation vulnerability exists in the Windows Projected File System (ProjFS) due to improper link resolution (CWE-59). The flaw occurs when the system follows a symbolic link or junction point without properly validating the target, allowing a local attacker with low privileges to redirect file operations to sensitive system locations. By exploiting this 'link following' behavior, an attacker can achieve SYSTEM-level privileges. The attack requires local authentication but no user interaction. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2019 All versions
  • Microsoft Windows Server 2022 All versions

Timeline

  • 2026-07-14: advisory: Microsoft published the vulnerability details and security updates.

References

Related threats