CVE-2026-50458

Published Jul 14, 2026

Last updated 2 months ago

CVSS high 7.8
Microsoft Brokering File System

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-50458 is a use-after-free vulnerability found within the Microsoft Brokering File System (BFS), specifically impacting the `bfs.sys` Windows kernel minifilter driver. This flaw allows an authorized local attacker to elevate privileges on an affected Windows host. The vulnerability arises from a race condition during concurrent operations on BFS objects, where a kernel object can be freed while still being referenced by another thread, leading to a use-after-free condition. Exploitation of CVE-2026-50458 can enable an attacker to achieve arbitrary code execution and gain full control over the compromised system, impacting confidentiality, integrity, and availability. Affected systems include various versions of Windows 11 (24H2, 25H2, and 26H1) and Windows Server 2025. Microsoft released an advisory and corresponding patches for this vulnerability on July 14, 2026.

Description
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2025

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-362

Social media

Hype score
Not currently trending
  1. URGENT ADVISORY🚨: Windows 11 and Windows Server 2025 are exposed to a high-severity vulnerability in Microsoft's Brokering File System (BFS), identified as CVE-2026-50458. CLICK HERE FOR MORE INFORMATION👇https://t.co/9QXZAQzGcM https://t.co/7sqetzw86Z

    @DACK_WOLF217

    1 Aug 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Windowsでサンドボックス内のアプリとOS資源の間を取り持つドライバーbfs[.]sysに、AIエージェント向けとみられる新しいAppContainer対応を加えた経路でだけ参照カウントの加算が抜け落ち、カーネルのUse-After-Freeに

    @MalwareBibleJP

    25 Jul 2026

    1823 Impressions

    2 Retweets

    9 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  3. URGENT ADVISORY🚨: Windows 11 and Windows Server 2025 are exposed to a high-severity vulnerability in Microsoft's Brokering File System (BFS), identified as CVE-2026-50458. CLICK HERE FOR MORE INFORMATION👇 https://t.co/Rxg1bCf1xd #JaCIRT #CIRT #Cybersecurity #Windows https:/

    @cirtgovjm

    24 Jul 2026

    116 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. ⚠️ A high-severity vulnerability (CVE-2026-50458, CVSS 7.8) in Windows' Brokering File System driver (bfs.sys) lets a local attacker escalate privileges to SYSTEM via a use-after-free race condition, affecting Windows 11 (24H2/25H2/26H1) and Windows Server 2025 — no active

    @techepages

    23 Jul 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. MicrosoftのBrokering File Systemに、ローカルの低権限ユーザーやサンドボックス内のコードからSYSTEM権限を取得できる脆弱性CVE-2026-50458が見つかり、7月の更新で修正された。

    @yousukezan

    23 Jul 2026

    1615 Impressions

    2 Retweets

    3 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  6. Microsoft has patched CVE-2026-50458, a critical vulnerability in the Brokering File System (BFS) driver affecting Windows 11 and Server 2025. This flaw allows local attackers to escalate privileges, posing significant security risks. Immediate updates are essential to safeguard

    @dailytechonx

    23 Jul 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.