Information disclosure in Microsoft Windows and Windows Server - CVE-2026-50431
Published: July 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an information disclosure issue in Windows Quality of Service (QoS) Packet Scheduler when handling network traffic. A remote attacker can send crafted traffic to disclose sensitive information.
The issue can disclose certain kernel memory addresses, which could aid further attacks.
Affected software
Windows Server
How to mitigate CVE-2026-50431
Windows Server - addressed in versions 2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158