Windows NTLM Spoofing Vulnerability in Microsoft Products
CVE-2026-50508

6.5MEDIUM

What is CVE-2026-50508?

The vulnerability in Windows NTLM permits unauthorized actors to access sensitive information, enabling potential spoofing attacks across the network. This security flaw highlights the need for immediate attention to protect against unauthorized access and maintain the integrity of user data. Users and administrators are encouraged to apply mitigations and updates provided by the vendor to safeguard against these risks.

Affected Version(s)

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9234

Windows 11 version 22H2 ARM64-based Systems 10.0.22621.0 < 10.0.22631.7219

Windows Server 2012 (Server Core installation) x64-based Systems 6.2.9200.0 < 6.2.9200.26132

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.