CVE-2026-50508
Published Jun 9, 2026Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- evidence mentions
- 4
- Buzz score
- 25.6
Vendor/product archive
1,684 CVEs tagged to microsoft / windows_11_22h2 — 35 Critical, 1,163 High, 480 Medium, 6 Low, 0 Unrated.
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.
Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack.
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.