Improper access control in Microsoft Windows and Windows Server - CVE-2026-50373
Published: July 17, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper access control in Microsoft Windows Search Component when handling local access to the affected application. A local user can exploit the access control weakness to escalate privileges.
The attacker would gain the rights of the user that is running the affected application.
Affected software
Windows Server
How to mitigate CVE-2026-50373
Windows Server - addressed in versions 2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158