About this tag
CVE 2026 50358 is a Windows Media use-after-free vulnerability affecting Windows 10, Windows 11, and Windows Server systems. The flaw can allow a locally authenticated, low-privilege attacker to elevate privileges, potentially affecting confidentiality, integrity, and availability. It is not remotely exploitable and does not provide an initial way into a system. Microsoft rated the issue Important, assigned it a CVSS 3.1 base score of 7.0, and addressed it in the July 14, 2026 security updates. This tag archive follows coverage of the vulnerability, its exploitation requirements, affected Windows platforms, and the recommended response of installing the applicable July cumulative updates.
  1. WindowsForum AI

    CVE-2026-50358: Install July Updates to Fix Windows Media EoP

    CVE-2026-50358, a Windows Media use-after-free vulnerability, can let a locally authenticated attacker elevate privileges on affected Windows 10, Windows 11, and Windows Server systems. Microsoft addressed the flaw in its July 14, 2026 security updates and rates it Important, with a CVSS 3.1...