Junglewise Threat Intelligence

CVE-2026-50498: Microsoft Windows UDFS privilege escalation

CVE-2026-50498 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows driver responsible for reading Universal Disk Format (UDF) files, which are commonly used on optical media like DVDs and Blu-rays. If a user is tricked into opening a malicious file or mounting a specially crafted disk image, an attacker could gain full control over the computer. This could allow them to install programs, view or delete sensitive data, or create new user accounts with full administrative rights.

Technical details

An elevation of privilege vulnerability exists in the Microsoft Windows Universal Disk Format File System Driver (UDFS) due to improper handling of objects in memory. The flaw is characterized by an integer underflow and out-of-bounds read condition within the driver component. To exploit this, an attacker would typically need to convince a user to mount a malicious UDF file system or open a specially crafted file. Successful exploitation allows a local attacker to execute arbitrary code with SYSTEM privileges, effectively bypassing security boundaries on the affected host. Microsoft has released security updates to address this issue across supported versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All versions

Timeline

  • 2026-07-14: disclosed: Initial disclosure by Microsoft and NVD.
  • 2026-07-14: patched: Security updates made available via Microsoft Update Guide.

References

Related threats