Integer underflow in Microsoft Windows and Windows Server - CVE-2026-50300
Published: July 17, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to integer underflow in Windows Kernel when handling crafted local operations. A local user can trigger the integer underflow to disclose sensitive information.
An attacker who successfully exploits this vulnerability could read small portions of heap memory.
Affected software
Windows Server
How to mitigate CVE-2026-50300
Windows Server - addressed in versions 2012 R2 6.3.9600.23291, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158