Junglewise Threat Intelligence

CVE-2026-50669: Microsoft Windows Telephony Service privilege escalation

CVE-2026-50669 · Severity: high · CVSS 7 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows Telephony Service, a component that manages phone and modem connections on Windows computers. An attacker who already has basic access to a system could exploit this flaw to gain full administrative control. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

This vulnerability is a race condition (CWE-362) that leads to a use-after-free (CWE-416) condition within the Windows Telephony Service. The flaw occurs due to improper synchronization when multiple threads access shared resources concurrently. An attacker with low-privileged local access can exploit this timing issue to execute code with elevated system privileges. The attack requires the attacker to win a race condition, making the exploit complexity high, but it does not require user interaction. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 Versions 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All editions

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats