CVE-2026-50432
Analyzed Analyzed - Analysis Complete

Use After Free in Windows Virtual Filtering Platform

Vulnerability report for CVE-2026-50432, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 20 associated CPEs
Vendor Product Version / Range
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50432 is a use-after-free vulnerability in the Windows Virtual Filtering Platform (VFP). This type of vulnerability occurs when a program continues to use memory after it has been freed, which can lead to unexpected behavior or crashes.

In this case, an authorized attacker with low privileges (PR:L) can exploit this flaw over a network (AV:N) to cause a denial of service (DoS). The attack complexity is high (AC:H), meaning it requires specific conditions to be met for successful exploitation.

The vulnerability does not affect confidentiality or integrity (C:N/I:N) but can severely impact availability (A:H), leading to service disruptions.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the presence of CVE-2026-50432 on a network or system. Detection typically involves checking for vulnerable software versions or monitoring for unusual network behavior related to the Windows Virtual Filtering Platform (VFP).

To detect this vulnerability, you may need to: 1) Verify the installed version of Windows and any related VFP components against Microsoft's security updates. 2) Use network monitoring tools to observe abnormal traffic patterns that could indicate exploitation attempts, such as unexpected service disruptions or crashes in VFP-related processes.

For precise detection steps, refer to Microsoft's official guidance or security tools that support vulnerability scanning for Windows components.

Impact Analysis

If you are using a system with the Windows Virtual Filtering Platform (VFP), this vulnerability could impact you in the following ways:

  • Denial of Service (DoS): An authorized attacker could exploit this vulnerability to crash or disrupt services that rely on VFP, leading to downtime or unavailability of network-dependent applications.
  • Network-based exploitation: Since the attack vector is network-based (AV:N), the attacker does not need physical access to the system but must have authorized (low-privilege) access to the network.
  • No data theft or modification: The vulnerability does not allow for unauthorized access to or modification of data, as it only affects system availability.
Compliance Impact

The impact of this vulnerability on compliance with standards and regulations depends on the context of its exploitation and the systems affected:

  • GDPR: If the denial of service disrupts services processing personal data, it could lead to non-compliance with GDPR's availability requirements (Article 32). However, since this vulnerability does not involve unauthorized data access or disclosure, it is less likely to directly violate GDPR's core data protection principles.
  • HIPAA: For organizations handling protected health information (PHI), a denial of service could disrupt access to critical systems, potentially violating HIPAA's availability requirements. However, like GDPR, this vulnerability does not directly expose PHI, so the compliance risk is lower unless the disruption affects patient care or data integrity.
  • Other standards: Compliance frameworks like ISO 27001 or NIST SP 800-53 emphasize system availability. A successful DoS attack could demonstrate a failure to meet these requirements, particularly if the affected system is critical to operations.

Overall, while this vulnerability primarily affects availability, organizations should assess its potential impact on their specific compliance obligations, especially if the affected systems are part of regulated workflows.

Mitigation Strategies

Based on the provided context, the following immediate steps are recommended to mitigate CVE-2026-50432:

  • Apply the latest security updates from Microsoft as soon as they are available. Refer to the Microsoft Security Response Center (MSRC) update guide for CVE-2026-50432 for patch details.
  • Restrict network access to systems running the Windows Virtual Filtering Platform (VFP) to minimize exposure to potential attackers.
  • Monitor systems for signs of exploitation, such as unexpected crashes or service disruptions, and investigate any anomalies promptly.
  • Ensure that only authorized users have access to systems running VFP, as the vulnerability requires an authorized attacker.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50432. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart