• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-50369: elevation of privilege in Microsoft Windows 10 Version 1607

An authenticated attacker with network access can elevate privileges on Windows systems via a use-after-free bug in Remote Desktop Services (CVE-2026-50369). Affected releases include the Windows 10 Version 1607 branch (10.0.14393.0 through before 10.0.14393.9339) and multiple other Windows 10, Windows 11 and Windows Server branches listed in vendor advisories; attacker interaction requires valid authorization over the network. Microsoft has published fixes for the affected branches.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
8.8HIGH
EPSS
0.00701
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists for this remote elevation-of-privilege bug, so prioritize installing Microsoft's fixes or blocking Remote Desktop exposure immediately.

What is CVE-2026-50369?

An authenticated attacker with network access can elevate privileges on Windows systems via a use-after-free bug in Remote Desktop Services (CVE-2026-50369). Affected releases include the Windows 10 Version 1607 branch (10.0.14393.0 through before 10.0.14393.9339) and multiple other Windows 10, Windows 11 and Windows Server branches listed in vendor advisories; attacker interaction requires valid authorization over the network. Microsoft has published fixes for the affected branches. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.933910.0.14393.9339
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.902010.0.17763.9020
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.754810.0.19044.7548
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.754810.0.19045.7548
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.887510.0.26100.8875
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.887510.0.26200.8875
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.252510.0.28000.2525
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.262266.2.9200.26226
Windows Server 2012 (Server Core installation) 6.x6.2.9200.0 – before 6.2.9200.262266.2.9200.26226
Windows Server 2012 R2 6.x6.3.9600.0 – before 6.3.9600.232916.3.9600.23291

Is CVE-2026-50369 being exploited?

Public exploit code is available.

How to fix CVE-2026-50369

  1. Apply Microsoft's updates that include the fixes (for example upgrade to at least 10.0.14393.9339 on the Windows 10 1607 branch).
  2. Patch other affected branches to their listed fixed builds (for example 10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548, 10.0.26100.8875, 10.0.26200.8875, 10.0.28000.2525 or the Windows Server fixes listed by Microsoft).
  3. If immediate patching is not possible, restrict Remote Desktop Services access with firewall rules and network segmentation to trusted hosts only.
  4. Monitor authentication and Remote Desktop logs for unusual logins or privilege escalation activity.

Frequently asked questions

Is CVE-2026-50369 being actively exploited?

Public exploit code is available for CVE-2026-50369, indicating a real risk of active exploitation.

Which Windows 10 Version 1607 versions are affected by CVE-2026-50369?

Windows 10 Version 1607 systems with builds from 10.0.14393.0 up to before 10.0.14393.9339 are affected; other Windows 10, Windows 11 and Windows Server branches are also listed as affected by Microsoft.

Is there a patch for CVE-2026-50369?

Yes. Microsoft published fixes; for the Windows 10 1607 branch the fixed build is 10.0.14393.9339 and comparable fixed builds are provided for other affected branches.

Does CVE-2026-50369 require authentication?

Yes. The vulnerability requires an authorized user connecting over the network to Remote Desktop Services.

References