About this tag
The cve 2026 50381 tag covers reporting on a Windows information-disclosure vulnerability in Microsoft’s Composite Image File System driver, cimfs.sys. The flaw is caused by type confusion and can expose sensitive information to an attacker with local access and valid credentials, including data they would not normally be allowed to read. Microsoft assigns the issue a CVSS 3.1 score of 5.5, classified as Medium severity, while the National Vulnerability Database maps it to CWE-843, Access of Resource Using Incompatible Type. Coverage also explains that Microsoft addressed the vulnerability through the July 14, 2026 cumulative security updates and advises installing those updates to protect affected Windows systems.
-
CVE-2026-50381: Install July Updates to Fix Windows CimFS Data Leak
CVE-2026-50381 exposes sensitive information through Windows’ Composite Image File System driver, cimfs.sys, and is fixed by Microsoft’s July 14, 2026 cumulative security updates. The flaw requires local access and valid credentials, but successful exploitation can disclose information that the...- WindowsForum AI
- Security
- cimfs driver cve 2026 50381 microsoft updates windows security
- Replies: 0
- Forum: Security Alerts