CVE-2026-50509
Analyzed Analyzed - Analysis Complete

Windows Wireless Wide Area Network Service Deserialization Flaw

Vulnerability report for CVE-2026-50509, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 19 associated CPEs
Vendor Product Version / Range
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50509 is a vulnerability in the Windows Wireless Wide Area Network Service. It involves the deserialization of untrusted data, which means the service improperly processes data received from an untrusted source.

An authorized attacker with local access to the system can exploit this flaw to elevate their privileges. This could allow them to gain higher-level permissions on the affected system, potentially taking full control.

Detection Guidance

Detection requires checking for unauthorized privilege escalation attempts in Windows Wireless Wide Area Network Service. Monitor system logs for unusual activity in wwansvc.dll or related processes. Use Windows Event Viewer to inspect Security logs for Event ID 4688 (process creation) with elevated privileges. Check for unexpected changes in service configurations or registry keys under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WwanSvc.

Impact Analysis

If you are using a system with the Windows Wireless Wide Area Network Service, this vulnerability could have several impacts:

  • An attacker with local access and low privileges could exploit this to gain administrative or SYSTEM-level privileges on your machine.
  • Once elevated, the attacker could install malicious software, modify or delete data, or create new accounts with full user rights.
  • This could lead to unauthorized access to sensitive information, disruption of services, or further compromise of your network.
Compliance Impact

This vulnerability could impact compliance with several standards and regulations, depending on the context of your organization:

  • GDPR: If the affected system processes personal data of EU citizens, a successful exploit could lead to unauthorized access or disclosure of this data. This may violate GDPR requirements for data protection and breach notification.
  • HIPAA: For organizations handling protected health information (PHI), this vulnerability could result in unauthorized access to PHI, violating HIPAA's security and privacy rules.
  • Other standards like ISO 27001 or NIST frameworks require organizations to manage vulnerabilities and protect systems from unauthorized access. Failure to patch this vulnerability could result in non-compliance.

To maintain compliance, it is critical to apply security updates promptly and ensure systems are protected against privilege escalation attacks.

Mitigation Strategies

Apply the security update provided by Microsoft to address CVE-2026-50509. The update can be found in the Microsoft Update Guide for this vulnerability.

  • Ensure all systems running the affected Windows Wireless Wide Area Network Service are updated to the latest patched version.
  • Restrict local access to trusted users only, as the vulnerability requires local privileges to exploit.
  • Monitor Microsoft's security advisories for any additional guidance or updates related to this CVE.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50509. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart