MITRE ATT&CK CVE list for this attack path. Use risk scores and timeline to decide what to patch first and what to track next.
| CVE | Description | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|
| CVE-2026-50440 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally. | 7.8 | 0.19% | 2026-07-14 | 2026-07-21 |
| CVE-2026-50438 | Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. | 8.8 | 0.28% | 2026-07-14 | 2026-07-21 |
| CVE-2026-50427 | Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally. | 7.8 | 0.19% | 2026-07-14 | 2026-07-20 |
| CVE-2026-50424 | Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network. | 7.5 | 0.83% | 2026-07-14 | 2026-07-20 |
| CVE-2026-50414 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. | 7.5 | 0.47% | 2026-07-14 | 2026-07-20 |
| CVE-2026-50404 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally. | 7.0 | 0.16% | 2026-07-14 | 2026-07-20 |
| CVE-2026-50403 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. | 7.0 | 0.16% | 2026-07-14 | 2026-07-20 |
| CVE-2026-50398 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. | 8.8 | 0.47% | 2026-07-14 | 2026-07-15 |
| CVE-2026-50385 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. | 8.8 | 0.19% | 2026-07-14 | 2026-07-20 |
| CVE-2026-50382 | Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally. | 8.8 | 0.28% | 2026-07-14 | 2026-07-20 |
| CVE-2026-50379 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. | 7.5 | 0.36% | 2026-07-14 | 2026-07-20 |
| CVE-2026-50378 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally. | 7.8 | 0.24% | 2026-07-14 | 2026-07-21 |
| CVE-2026-50376 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | 6.5 | 0.89% | 2026-07-14 | 2026-07-20 |
| CVE-2026-50371 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally. | 7.0 | 0.19% | 2026-07-14 | 2026-07-20 |
| CVE-2026-50369 | Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. | 8.8 | 0.65% | 2026-07-14 | 2026-07-20 |
| CVE-2026-50367 | Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | 7.8 | 0.24% | 2026-07-14 | 2026-07-20 |
| CVE-2026-50361 | Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 7.8 | 0.19% | 2026-07-14 | 2026-07-20 |
| CVE-2026-50348 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network. | 7.0 | 0.33% | 2026-07-14 | 2026-07-20 |
| CVE-2026-50345 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. | 7.0 | 0.19% | 2026-07-14 | 2026-07-20 |
| CVE-2026-50337 | Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally. | 7.8 | 0.32% | 2026-07-14 | 2026-07-20 |