CVE-2026-50381
Microsoft · Published July 14, 2026
5.5
CVSS v3.1
MEDIUMPatch availableGet patch
Description
Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability. Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.
Affected Products
- Windows Server 2022
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C