Junglewise Threat Intelligence

CVE-2026-50667: Microsoft Windows NTFS race condition privilege escalation

CVE-2026-50667 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows NTFS file system, which is responsible for how the computer stores and retrieves files on the hard drive. An attacker who already has basic access to a system could exploit this flaw to gain full administrative control. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

This vulnerability is classified as a race condition (CWE-362) within the Windows New Technology File System (NTFS) driver. It occurs due to improper synchronization when multiple processes or threads attempt to access a shared resource concurrently. An attacker with local access and low-level privileges can exploit this timing flaw to execute code with elevated system permissions. The vulnerability affects a wide range of Windows client and server versions, and Microsoft has released security updates to address the issue.

Affected products

  • Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 Versions 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 Standard and Server Core installations

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats