Junglewise Threat Intelligence

CVE-2026-50480: Microsoft Windows heap overflow in WPAD

CVE-2026-50480 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows 10 Version 1607, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows Server 2016. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows component responsible for automatically discovering web proxy settings. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could lead to the unauthorized access of sensitive data or the installation of malicious software across the corporate network.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in the Windows Web Proxy Auto-Discovery Protocol (WPAD) service. The flaw is triggered when the service improperly handles memory allocation during proxy discovery operations. An attacker with low-privileged local access can exploit this by running a specially crafted application, leading to arbitrary code execution with elevated system privileges. Microsoft has released security updates to address this issue across affected versions of Windows 10 and Windows Server.

Affected products

  • Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
  • Microsoft Windows Server 2012 / 2012 R2 / 2016 Various versions prior to July 2026 updates

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats