MicrosoftCVE-2026-50450
Microsoft Windows Wireless Wide Area Network Service: race condition
High7.8CVE-2026-50450 · Published Jul 14, 2026 · updated Jul 22, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Windows 10 Version 1809 Product | >= 10.0.17763.0, < 10.0.17763.9020 | 10.0.17763.9020 |
| Windows 10 Version 21H2 Product | >= 10.0.19044.0, < 10.0.19044.7548 | 10.0.19044.7548 |
| Windows 10 Version 22H2 Product | >= 10.0.19045.0, < 10.0.19045.7548 | 10.0.19045.7548 |
| Windows 11 Version 24H2 Product | >= 10.0.26100.0, < 10.0.26100.8875 | 10.0.26100.8875 |
| Windows 11 Version 25H2 Product | >= 10.0.26200.0, < 10.0.26200.8875 | 10.0.26200.8875 |
| Windows 11 version 26H1 Product | >= 10.0.28000.0, < 10.0.28000.2525 | 10.0.28000.2525 |
| Windows Server 2019 Product | >= 10.0.17763.0, < 10.0.17763.9020 | 10.0.17763.9020 |
| Windows Server 2019 (Server Core installation) Product | >= 10.0.17763.0, < 10.0.17763.9020 | 10.0.17763.9020 |
| Windows Server 2022 Product | >= 10.0.20348.0, < 10.0.20348.5386 | 10.0.20348.5386 |
| Windows Server 2025 Product | >= 10.0.26100.0, < 10.0.26100.33158 | 10.0.26100.33158 |
| Windows Server 2025 (Server Core installation) Product | >= 10.0.26100.0, < 10.0.26100.33158 | 10.0.26100.33158 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-362
More Microsoft advisories
All Microsoft| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 14 | Secret exfiltration vulnerability | High | 1.128.1 |
| Jul 14 | Workspace Trust Security Feature Bypass Vulnerability | High | 1.128.1 |
| Jul 14 | Remote Code Execution Vulnerability | High | 1.128.1 |
| Jul 14 | Microsoft .NET 8.0: unsafe deserialization | High7.8 | 8.0.29+9 more |
| Jul 14 | Microsoft .NET 8.0: code injection | High7.8 | 8.0.29+10 more |
| Jul 14 | Microsoft .NET 10.0: resource exhaustion | High7.5 | 10.0.10+5 more |