Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4622 articles · 179959 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-50343EXPLOITEDPATCHED
microsoft · windows_10_1809

Microsoft Install Service Elevation of Privilege Vulnerability

Description

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

Affected Products

VendorProductVersions
microsoftwindows_10_180910.0.17763.0, 10.0.19044.0, 10.0.19045.0, 10.0.26100.0, 10.0.26200.0, 10.0.28000.0, 10.0.17763.0, 10.0.17763.0, 10.0.20348.0, 10.0.26100.0, 10.0.26100.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftwindows_10_21h2cve_cpe95%
microsoftwindows_server_2025cve_cpe95%
microsoftwindows_10_22h2cve_cpe95%
microsoftwindows_11_24h2cve_cpe95%
microsoftwindows_11_25h2cve_cpe95%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50343(vendor-advisory, patch)

Related News (5 articles)

Tier E
Lobsters Security1d ago
Dark Elevator: Windows Install Service Local Privilege Escalation (CVE-2026-50343)
→ No new info (linked only)
Tier B
CERT-FR9d ago
Multiples vulnérabilités dans Microsoft Windows (15 juillet 2026)
→ No new info (linked only)
Tier C
Qualys Blog9d ago
Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review 
→ No new info (linked only)
Tier C
VulDB9d ago
CVE-2026-50343 | Microsoft Windows up to Server 2025 Microsoft Install Service improper authorization
→ No new info (linked only)
Tier A
Microsoft MSRC9d ago
CVE-2026-50343 Microsoft Install Service Elevation of Privilege Vulnerability
→ No new info (linked only)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
10.0.17763.902010.0.19044.754810.0.19045.754810.0.26100.887510.0.26200.887510.0.28000.226910.0.20348.538610.0.26100.33158
CWECWE-269
PublishedJul 14, 2026
Last enriched9d agov3
Trending Score63
Source articles5
Independent5
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-50522EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 142
CRITICALCVE-2026-58644EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 124
HIGHCVE-2026-56164EXPKEV
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Trending: 92
HIGHCVE-2026-56155EXPKEV
Active Directory Federation Services Elevation of Privilege Vulnerability
Trending: 88
CRITICALCVE-2026-45659EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 54

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: description, exploitAvailable, activelyExploited
Jul 14, 2026
Updated: affectedVersions, cweIds
Jul 14, 2026
Actively Exploited
Jul 24, 2026
Exploit Available
Jul 24, 2026
Patch Available
Jul 24, 2026

Version History

v3
Last enriched 9d ago
v3Tier C9d ago

Updated affected versions to include 'up to Server 2025', changed severity to MEDIUM, and noted no exploit is available.

affectedVersionscweIds
via VulDB
v2Tier A9d ago

Added a detailed description of the vulnerability and marked it as actively exploited with an exploit available.

descriptionexploitAvailableactivelyExploited
via Microsoft MSRC
v19d ago

Initial creation