Junglewise Threat Intelligence

CVE-2026-50502: Microsoft Windows Event Logging Service remote code execution

CVE-2026-50502 · Severity: high · CVSS 8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Event Logging Service, which is responsible for recording system and application events. An authorized user on the network could exploit this flaw to execute unauthorized code on a target system. This could lead to a complete compromise of the affected machine, including data theft or service disruption.

Technical details

This vulnerability is classified as an insufficient granularity of access control (CWE-1220) within the Windows Event Logging Service. An attacker with low-privileged credentials can exploit this flaw over the network, though it requires some level of user interaction. Successful exploitation allows for remote code execution (RCE) with the privileges of the service. The vulnerability affects a wide range of Windows client and server versions, including Windows 10, Windows 11, and Windows Server 2012. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All versions

Timeline

  • 2026-07-14: disclosed: Initial publication by Microsoft and NVD
  • 2026-07-14: advisory: MSRC advisory published

References

Related threats