CVE-2026-50381
Analyzed Analyzed - Analysis Complete

Type Confusion in Composite Image File System Driver

Vulnerability report for CVE-2026-50381, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 14 associated CPEs
Vendor Product Version / Range
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-843 The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50381 is a type confusion vulnerability in the Composite Image File System Driver. Type confusion occurs when a program accesses a resource (like memory or a file) using an incompatible data type, leading to unintended behavior.

In this case, an authorized attacker with local access can exploit this flaw to disclose sensitive information from the system. The vulnerability does not allow remote exploitation or code execution but can lead to information leaks.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the presence of CVE-2026-50381 on a network or system. Detection typically involves checking for vulnerable versions of the Composite Image File System Driver or using security tools that can identify type confusion vulnerabilities in drivers.

For Microsoft-related vulnerabilities, you may refer to the Microsoft Security Response Center (MSRC) or use Windows Update to check for applicable patches. Additionally, endpoint detection and response (EDR) tools or vulnerability scanners may help identify affected systems.

Impact Analysis

If you are affected by this vulnerability, the impact includes:

  • Information disclosure: An attacker with local access and authorization could read sensitive data from your system, such as files or memory contents.
  • Privilege escalation risk: While the vulnerability itself does not grant elevated privileges, disclosed information could be used to facilitate further attacks.

The CVSS score of 5.5 (Medium severity) indicates that the vulnerability is significant but requires local access and some level of authorization to exploit.

Compliance Impact

This vulnerability could impact compliance with standards and regulations in the following ways:

  • GDPR: If the disclosed information includes personal data of EU citizens, unauthorized access could violate GDPR requirements for data protection and confidentiality.
  • HIPAA: If the system handles protected health information (PHI), unauthorized disclosure could breach HIPAA's privacy and security rules.
  • Other standards: Compliance frameworks like ISO 27001 or NIST SP 800-53 require organizations to protect against unauthorized information disclosure. Failure to patch this vulnerability could result in non-compliance.

Organizations should assess whether the affected system processes regulated data and take appropriate remediation steps to maintain compliance.

Mitigation Strategies

Based on the provided context, the following steps are recommended to mitigate CVE-2026-50381:

  • Apply the latest security updates from Microsoft as soon as they are available. Refer to the Microsoft Update Guide for CVE-2026-50381 for patch details.
  • Restrict local access to systems to only authorized users, as the vulnerability requires local access to exploit.
  • Monitor Microsoft advisories for additional guidance or workarounds if a patch is not immediately available.
  • Consider using security tools to detect and prevent exploitation attempts, such as endpoint protection platforms or intrusion detection systems.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50381. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart