DIRAS TAKE
Urgent: public exploit code exists, so prioritize patching systems with any affected Windows 10, Windows 11, or Windows Server branch; the availability of exploit code makes updates and immediate mitigations critical.
What is CVE-2026-50343?
An authorized local user can elevate privileges on Microsoft Windows systems via an improper privilege management flaw in the Install Service. CVE-2026-50343 permits privilege escalation when a local account interacts with the vulnerable component. Affected releases include multiple Windows 10, Windows 11, and Windows Server branches listed below; an attacker needs local access with an authorized account — no user interaction beyond that is required. Administrators should treat this as a high-severity local elevation issue and apply vendor updates or mitigations promptly. The weakness is classified as CWE-269 (Improper Privilege Management).
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1809 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9020 | 10.0.17763.9020 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7548 | 10.0.19044.7548 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7548 | 10.0.19045.7548 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.8875 | 10.0.26100.8875 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.8875 | 10.0.26200.8875 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2525 | 10.0.28000.2525 |
| Windows Server 2019 10.x | 10.0.17763.0 – before 10.0.17763.9020 | 10.0.17763.9020 |
| Windows Server 2019 (Server Core installation) 10.x | 10.0.17763.0 – before 10.0.17763.9020 | 10.0.17763.9020 |
| Windows Server 2022 10.x | 10.0.20348.0 – before 10.0.20348.5386 | 10.0.20348.5386 |
| Windows Server 2025 10.x | 10.0.26100.0 – before 10.0.26100.33158 | 10.0.26100.33158 |
Is CVE-2026-50343 being exploited?
Public exploit code is available.
How to fix CVE-2026-50343
- Install the vendor fixes for your branch: update to 10.0.17763.9020 for Windows 10 Version 1809 and Server 2019, 10.0.19044.7548 for Windows 10 21H2, 10.0.19045.7548 for Windows 10 22H2, 10.0.26100.8875 for Windows 11 24H2, 10.0.26200.8875 for Windows 11 25H2, 10.0.28000.2525 for Windows 11 26H1, 10.0.20348.5386 for Server 2022, and 10.0.26100.33158 for Server 2025.
- If you cannot patch immediately, restrict local account access and remove unnecessary administrative privileges from users.
- Monitor host event logs for unexpected privilege elevation and audit administrative account activity.
- Follow Microsoft guidance for any additional vendor-recommended mitigations and verify updates are applied.
Frequently asked questions
Is CVE-2026-50343 being actively exploited?
Public exploit code is available for CVE-2026-50343.
Which Windows 10 Version 1809 versions are affected by CVE-2026-50343?
Windows 10 Version 1809 builds 10.0.17763.0 through before 10.0.17763.9020 are affected; the issue is fixed in 10.0.17763.9020.
Is there a patch for CVE-2026-50343?
Yes. Microsoft published fixes; each affected branch has a fixed build (for example 10.0.17763.9020 for 1809 and corresponding fixed builds for other Windows 10, Windows 11, and Server branches).
Does CVE-2026-50343 require authentication?
Yes. CVE-2026-50343 requires an authorized local account; it is a local privilege escalation rather than a remote unauthenticated flaw.
References
- nvd.nist.gov/vuln/detail/CVE-2026-50343
- cve.org/CVERecord?id=CVE-2026-50343
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50343
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026