Junglewise Threat Intelligence

CVE-2026-50674: Microsoft Windows USB Print Driver use after free privilege escalation

CVE-2026-50674 · Severity: high · CVSS 7 · Published 2026-07-14

Technologies: Microsoft Windows 11 Version 24H2, Microsoft Windows 11 Version 26H1, Microsoft Windows Server 2025, Microsoft Windows 11, Microsoft Windows 11 Version 25H2. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows USB Print Driver, which manages communication between the operating system and USB-connected printers. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could lead to the theft of sensitive data, the installation of malicious software, or a complete system takeover.

Technical details

A use-after-free vulnerability (CWE-416) exists in the Windows USB Print Driver. The flaw is triggered when the driver incorrectly manages memory objects, allowing an attacker to reuse a memory pointer after it has been freed. To exploit this, an attacker must have local access to the system with low-level privileges and successfully win a race condition or navigate high complexity execution paths (AC:H). Successful exploitation allows the attacker to execute arbitrary code with elevated kernel-mode privileges. Microsoft has released security updates to address this issue across affected versions of Windows 11 and Windows Server 2025.

Affected products

  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
  • Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2525
  • Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats