Junglewise Threat Intelligence

CVE-2026-50500: Microsoft Windows Netlogon use after free privilege escalation

CVE-2026-50500 · Severity: high · CVSS 7.5 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Netlogon service, which manages user authentication and domain connectivity. An attacker who already has basic access to the network could exploit this flaw to gain higher-level administrative privileges. This could allow an unauthorized user to take control of sensitive systems or access restricted data across the corporate network.

Technical details

A use-after-free (UAF) vulnerability exists in the Microsoft Windows Netlogon service (CWE-416). The flaw is triggered when the service incorrectly manages memory objects during network-based authentication requests. An attacker with low-privileged domain credentials can exploit this over the network to execute arbitrary code or gain elevated system privileges. While the attack vector is network-based, the complexity is rated as high, likely requiring specific timing or environmental conditions to successfully trigger the memory corruption. Microsoft has released security updates to address this issue across affected versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All versions

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory: Microsoft released security update guide for CVE-2026-50500

References

Related threats