Elevation of Privileges in Microsoft Brokering File System
CVE-2026-50458
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 14 July 2026
Badges
What is CVE-2026-50458?
CVE-2026-50458 is a vulnerability identified in the Microsoft Brokering File System, a component that facilitates the management and access of file resources within a networked environment. This vulnerability arises from a "use after free" error, which occurs when a program continues to reference a memory location after it has been freed. As a result, an authorized attacker could exploit this flaw to elevate their privileges on the local system. This could have significant consequences for various organizations, as it may allow unauthorized users to gain elevated access rights, thereby compromising sensitive information, executing malicious operations, or altering critical system configurations without authorization.
Potential impact of CVE-2026-50458
-
Unauthorized Access: The primary risk associated with this vulnerability is the potential for unauthorized users to gain elevated privileges. This could lead to access to restricted data and sensitive systems, undermining the security of organizational information.
-
System Compromise: Exploitation of this vulnerability could result in a complete compromise of affected systems, allowing attackers to install malware, exfiltrate data, or alter system configurations, destabilizing the overall IT stability.
-
Increased Attack Surface: With the potential for privilege elevation, the existence of this vulnerability could expand the attack surface for threat actors. If exploited, it may serve as a gateway for further attacks, leading to more severe incidents, including data breaches and propagation of malware throughout an organization's network.
Affected Version(s)
Windows 11 Version 24H2 ARM64-based Systems 10.0.26100.0 < 10.0.26100.8875
Windows 11 Version 25H2 ARM64-based Systems 10.0.26200.0 < 10.0.26200.8875
Windows 11 version 26H1 ARM64-based Systems 10.0.28000.0 < 10.0.28000.2525
News Articles
Windows 11 and Server 2025 Exposed to High-Severity Brokering File System Vulnerability
Windows 11 and Server 2025 are affected by a high-severity Brokering File System vulnerability that enables local privilege escalation.
1 week ago

References
CVSS V3.1
Timeline
- πΎ
Exploit known to exist
- π°
First article discovered by Cybersecuritynews
Vulnerability published
Vulnerability Reserved