Junglewise Threat Intelligence

CVE-2026-50487: Microsoft Windows DNS use after free privilege escalation

CVE-2026-50487 · Severity: high · CVSS 8.1 · Published 2026-07-14

Technologies: Microsoft Windows 11 Version 26H1, Microsoft Windows 11 Version 24H2, Microsoft Windows Server 2025, Microsoft Windows 11, Microsoft Windows 11 Version 25H2. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Microsoft Windows DNS service, which is responsible for translating human-readable domain names into IP addresses. An unauthorized attacker could exploit this flaw over a network to gain elevated system privileges. This could allow an attacker to take control of affected servers or workstations, potentially leading to data theft or service disruption.

Technical details

A use-after-free (CWE-416) vulnerability exists in the Microsoft Windows DNS server and client components. The flaw is triggered when the system improperly handles memory objects during DNS processing, allowing an unauthenticated attacker to execute code or escalate privileges via specially crafted network requests. While the attack vector is network-based, the complexity is rated as high, suggesting specific timing or environmental conditions are required for successful exploitation. Affected systems include Windows 11 and Windows Server 2025; users should apply the latest security updates from Microsoft to mitigate this risk.

Affected products

  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
  • Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
  • Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158

Timeline

  • 2026-07-14: disclosed: Initial publication of CVE-2026-50487 by Microsoft and NVD.

References

Related threats