MITRE ATT&CK CVE list for this attack path. Use risk scores and timeline to decide what to patch first and what to track next.
| CVE | 説明 | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|
| CVE-2026-50672 | Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. | 7.0 | 0.16% | 2026-07-14 | 2026-07-22 |
| CVE-2026-50669 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 7.0 | 0.16% | 2026-07-14 | 2026-07-22 |
| CVE-2026-50667 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally. | 7.8 | 2.16% | 2026-07-14 | 2026-07-22 |
| CVE-2026-50658 | Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally. | 7.0 | 0.19% | 2026-07-14 | 2026-07-22 |
| CVE-2026-50510 | Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally. | 7.8 | 0.31% | 2026-07-14 | 2026-07-22 |
| CVE-2026-50503 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. | 7.0 | 0.19% | 2026-07-14 | 2026-07-22 |
| CVE-2026-50479 | Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally. | 7.8 | 0.32% | 2026-07-14 | 2026-07-20 |
| CVE-2026-50469 | Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 7.8 | 0.28% | 2026-07-14 | 2026-07-22 |
| CVE-2026-50460 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network. | 8.1 | 0.52% | 2026-07-14 | 2026-07-22 |
| CVE-2026-50458 | Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 7.8 | 0.19% | 2026-07-14 | 2026-07-22 |
| CVE-2026-50457 | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | 7.8 | 0.19% | 2026-07-14 | 2026-07-22 |
| CVE-2026-50452 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network. | 7.0 | 0.26% | 2026-07-14 | 2026-07-22 |
| CVE-2026-50450 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally. | 7.8 | 0.16% | 2026-07-14 | 2026-07-22 |
| CVE-2026-50441 | Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. | 7.8 | 0.24% | 2026-07-14 | 2026-07-22 |
| CVE-2026-50440 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally. | 7.8 | 0.19% | 2026-07-14 | 2026-07-22 |
| CVE-2026-50438 | Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. | 8.8 | 0.28% | 2026-07-14 | 2026-07-21 |
| CVE-2026-50427 | Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally. | 7.8 | 0.19% | 2026-07-14 | 2026-07-22 |
| CVE-2026-50424 | Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network. | 7.5 | 0.83% | 2026-07-14 | 2026-07-22 |
| CVE-2026-50414 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. | 7.5 | 0.47% | 2026-07-14 | 2026-07-22 |
| CVE-2026-50404 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally. | 7.0 | 0.16% | 2026-07-14 | 2026-07-22 |