• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-50402: local privilege escalation in Microsoft Windows 10 Version 1607

Local users with low privileges can elevate to higher privileges on Windows systems due to an incorrect numeric type conversion in NTFS. CVE-2026-50402 affects multiple Windows branches (see affected list) including Windows 10 Version 1607 and later listed entries; required conditions are local access and a low-privilege account (no user interaction required). The vulnerability can lead to full confidentiality, integrity, and availability impact on affected machines.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
7.8HIGH
EPSS
0.00333
CWE
CWE-681
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists, so prioritize patching systems; apply the vendor fixes or block untrusted local accounts immediately.

What is CVE-2026-50402?

Local users with low privileges can elevate to higher privileges on Windows systems due to an incorrect numeric type conversion in NTFS. CVE-2026-50402 affects multiple Windows branches (see affected list) including Windows 10 Version 1607 and later listed entries; required conditions are local access and a low-privilege account (no user interaction required). The vulnerability can lead to full confidentiality, integrity, and availability impact on affected machines.

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.933910.0.14393.9339
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.902010.0.17763.9020
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.754810.0.19044.7548
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.754810.0.19045.7548
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.887510.0.26100.8875
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.887510.0.26200.8875
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.252510.0.28000.2525
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.262266.2.9200.26226
Windows Server 2012 (Server Core installation) 6.x6.2.9200.0 – before 6.2.9200.262266.2.9200.26226
Windows Server 2012 R2 6.x6.3.9600.0 – before 6.3.9600.232916.3.9600.23291

Is CVE-2026-50402 being exploited?

Public exploit code is available.

How to fix CVE-2026-50402

  1. Install Microsoft updates that move affected builds to the fixed versions listed (for example 10.0.14393.9339, 10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548, 10.0.26100.8875, 10.0.26200.8875, 10.0.28000.2525, 6.2.9200.26226, 6.3.9600.23291).
  2. Restrict and audit local accounts and limit who can log on interactively to affected hosts.
  3. Monitor systems for unusual privilege usage and review security event logs for escalation attempts.
  4. Follow Microsoft's guidance and deploy updates via your normal patch management processes.

Frequently asked questions

Is CVE-2026-50402 being actively exploited?

Public exploit code is available for CVE-2026-50402.

Which Windows versions are affected by CVE-2026-50402?

Affected versions include multiple Windows branches listed by Microsoft, such as Windows 10 Version 1607 (builds before 10.0.14393.9339) and additional Windows 10, Windows 11, and Windows Server builds shown in the affected list.

Is there a patch for CVE-2026-50402?

Yes; Microsoft published fixes that raise affected builds to the fixed versions named in the advisory (see affected[].fixed for exact build numbers).

Does CVE-2026-50402 require authentication?

Yes; the issue requires a local low-privilege account to exploit and does not require user interaction.

References