CyberICT

CVE-2026-50381

Microsoft · Published July 14, 2026

CVSS v3.1

MEDIUM
Patch availableGet patch

Description

Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability. Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.

Affected Products

  • Windows Server 2022
  • Windows 10 Version 21H2 for 32-bit Systems
  • Windows 10 Version 21H2 for ARM64-based Systems
  • Windows 10 Version 21H2 for x64-based Systems

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C