Junglewise Threat Intelligence

CVE-2026-50509: Microsoft Windows Wireless Wide Area Network Service privilege escalation

CVE-2026-50509 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows service responsible for managing wireless wide area network (WWAN) connections, such as cellular data. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to steal sensitive data, install malicious software, or disrupt business operations.

Technical details

A privilege escalation vulnerability exists in the Windows Wireless Wide Area Network Service (WwanSvc) due to the insecure deserialization of untrusted data (CWE-502). An attacker with local access and low-level user privileges can exploit this by providing specially crafted input to the service, leading to arbitrary code execution in a high-privilege context. The attack vector is local, requiring no user interaction and having low complexity. Microsoft has released security updates to address this issue across affected versions of Windows 10, Windows 11, and Windows Server 2016.

Affected products

  • Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 Versions 24H2, 25H2, 26H1
  • Microsoft Windows Server 2016 Standard and Server Core installations

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats