AI description
CVE-2026-50458 is a use-after-free vulnerability found within the Microsoft Brokering File System (BFS), specifically impacting the `bfs.sys` Windows kernel minifilter driver. This flaw allows an authorized local attacker to elevate privileges on an affected Windows host. The vulnerability arises from a race condition during concurrent operations on BFS objects, where a kernel object can be freed while still being referenced by another thread, leading to a use-after-free condition. Exploitation of CVE-2026-50458 can enable an attacker to achieve arbitrary code execution and gain full control over the compromised system, impacting confidentiality, integrity, and availability. Affected systems include various versions of Windows 11 (24H2, 25H2, and 26H1) and Windows Server 2025. Microsoft released an advisory and corresponding patches for this vulnerability on July 14, 2026.
- Description
- Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2025
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- secure@microsoft.com
- CWE-362
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
4
URGENT ADVISORY🚨: Windows 11 and Windows Server 2025 are exposed to a high-severity vulnerability in Microsoft's Brokering File System (BFS), identified as CVE-2026-50458. CLICK HERE FOR MORE INFORMATION👇 https://t.co/Rxg1bCf1xd #JaCIRT #CIRT #Cybersecurity #Windows https:/
@cirtgovjm
24 Jul 2026
87 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ A high-severity vulnerability (CVE-2026-50458, CVSS 7.8) in Windows' Brokering File System driver (bfs.sys) lets a local attacker escalate privileges to SYSTEM via a use-after-free race condition, affecting Windows 11 (24H2/25H2/26H1) and Windows Server 2025 — no active
@techepages
23 Jul 2026
55 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
MicrosoftのBrokering File Systemに、ローカルの低権限ユーザーやサンドボックス内のコードからSYSTEM権限を取得できる脆弱性CVE-2026-50458が見つかり、7月の更新で修正された。
@yousukezan
23 Jul 2026
1615 Impressions
2 Retweets
3 Likes
1 Bookmark
0 Replies
0 Quotes
Microsoft has patched CVE-2026-50458, a critical vulnerability in the Brokering File System (BFS) driver affecting Windows 11 and Server 2025. This flaw allows local attackers to escalate privileges, posing significant security risks. Immediate updates are essential to safeguard
@dailytechonx
23 Jul 2026
60 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "6D55C01A-5908-4CFC-BEB6-BBF3B6F0C5AF",
"versionEndExcluding": "10.0.26100.8875",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "740B730D-AEC5-4735-A122-B1CF8B3C364C",
"versionEndExcluding": "10.0.26100.8875",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "E26E96B6-1469-46AE-9CB5-AB7A0372C398",
"versionEndExcluding": "10.0.26200.8875",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "DDBCA9E4-7BFB-423A-B7A7-9CBF5625053D",
"versionEndExcluding": "10.0.26200.8875",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "8967AF79-CAD0-4F87-85A5-95D031C9FEFA",
"versionEndExcluding": "10.0.28000.2269",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "8E90830B-0BD1-4D01-9C7D-0F0E1828A0F5",
"versionEndExcluding": "10.0.28000.2525",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
"matchCriteriaId": "22BE2FE9-37B9-4FF2-B43A-60A3518E0F08",
"versionEndExcluding": "10.0.26100.33158",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]