CVE-2026-50431
Analyzed Analyzed - Analysis Complete

Windows QoS Packet Scheduler Information Disclosure

Vulnerability report for CVE-2026-50431, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 22 associated CPEs
Vendor Product Version / Range
microsoft windows_server_2012 r2
microsoft windows_server_2012 *
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50431 is an information disclosure vulnerability in the Windows Quality of Service (QoS) Packet Scheduler. This vulnerability allows an attacker with local access and low privileges to disclose sensitive information from the affected system.

The CVSS v3.1 score for this vulnerability is 5.5, with a vector of AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N. This means the attack requires local access (AV:L), low attack complexity (AC:L), low privileges (PR:L), no user interaction (UI:N), and has a high impact on confidentiality (C:H) but no impact on integrity (I:N) or availability (A:N).

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability (CVE-2026-50431) on a network or system. Detection may require checking for the presence of the vulnerable component or reviewing system logs for unusual QoS-related activity, but no explicit guidance is available in the given resources.

Impact Analysis

This vulnerability can impact you in the following ways:

  • An attacker with local access to your system could exploit this vulnerability to access sensitive information that they would not normally be able to view.
  • The disclosed information could be used to further compromise the system or network, leading to additional security breaches.
  • Since the vulnerability is rated as 'Important' by Microsoft, it poses a significant risk if left unpatched, especially in environments where confidentiality of data is critical.
Compliance Impact

This vulnerability can affect compliance with common standards and regulations in the following ways:

  • GDPR: If the disclosed information includes personal data of EU citizens, this vulnerability could lead to a breach of GDPR requirements, which mandate the protection of personal data. Unauthorized disclosure of such data could result in non-compliance and potential fines.
  • HIPAA: For organizations handling protected health information (PHI), this vulnerability could result in unauthorized access to sensitive patient data. This would violate HIPAA's Privacy and Security Rules, leading to potential penalties and legal consequences.
  • Other standards like ISO 27001 or NIST frameworks require organizations to protect sensitive information from unauthorized access. Failure to mitigate this vulnerability could result in non-compliance with these standards.
Mitigation Strategies

To mitigate CVE-2026-50431, follow these steps:

  • Apply the latest security updates provided by Microsoft for the Windows Quality of Service (QoS) Packet Scheduler. Refer to the Microsoft Update Guide for the specific patch related to this CVE.
  • Restrict local access to the system to minimize the risk of exploitation, as the vulnerability requires local access (AV:L in the CVSS vector).
  • Monitor Microsoft's official communications for additional guidance or workarounds if a patch is not immediately available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50431. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart