CVE-2026-50416
Analyzed Analyzed - Analysis Complete

Information Disclosure in Windows Win32K

Vulnerability report for CVE-2026-50416, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-20

Assigner: Microsoft Corporation

Description

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-20
Generated
2026-08-03
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50416 is an information disclosure vulnerability in Windows Win32K. It allows an authorized attacker with local access to expose sensitive information to an unauthorized actor. The vulnerability does not require user interaction and can be exploited under low-complexity conditions.

The CVSS v3.1 score for this vulnerability is 3.3, indicating a low severity. The vector AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N means the attack requires local access (AV:L), low attack complexity (AC:L), low privileges (PR:L), no user interaction (UI:N), and has a low impact on confidentiality (C:L) with no impact on integrity or availability.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the presence of CVE-2026-50416 on a network or system. This vulnerability involves local information disclosure in Windows Win32K, and detection may require monitoring for unusual access patterns or leveraging Microsoft-provided tools or updates.

To check for vulnerable systems, ensure that the latest security updates from Microsoft are applied. You can use Windows Update or tools like Microsoft Endpoint Configuration Manager to verify patch levels. Additionally, monitoring logs for unauthorized access attempts to sensitive information may help identify potential exploitation.

Impact Analysis

If exploited, this vulnerability could allow an attacker with local access to your system to disclose sensitive information. This might include system details, user data, or other confidential information stored or processed by the affected Windows component.

  • Unauthorized access to sensitive data, which could be used for further attacks or exploitation.
  • Potential exposure of personally identifiable information (PII) or other confidential data, depending on the system's role and the data it handles.

The impact is limited to systems where the attacker already has some level of authorized access, reducing the risk of remote exploitation.

Compliance Impact

This vulnerability could have implications for compliance with standards and regulations that require protection of sensitive data.

  • GDPR: If the disclosed information includes personal data of EU citizens, this could constitute a breach of GDPR, which mandates protection against unauthorized access or disclosure. Organizations may need to report the incident and could face penalties if proper safeguards were not in place.
  • HIPAA: For healthcare organizations, if the exposed data includes protected health information (PHI), this could violate HIPAA's Privacy Rule, which requires safeguards to prevent unauthorized access to PHI.
  • Other standards like PCI DSS (for payment card data) or industry-specific regulations may also be affected if the disclosed information falls under their scope.

Compliance impact depends on the nature of the exposed data and the organization's specific regulatory obligations. Organizations should assess whether the vulnerability could lead to a reportable breach under applicable laws.

Mitigation Strategies
  • Apply the latest security updates from Microsoft as soon as they are available. Refer to the Microsoft Security Update Guide for patches related to CVE-2026-50416.
  • Restrict local access to systems to only authorized users, as the vulnerability requires local privileges to exploit.
  • Monitor systems for unusual activity or unauthorized access attempts to sensitive information.
  • Review and enforce least-privilege principles to minimize the impact of potential exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50416. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart