CVE-2026-50650
Microsoft · Published July 14, 2026
7.8
CVSS v3.1
HIGHPatch availableGet patch
Description
.NET Framework Elevation of Privilege Vulnerability. Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Affected Products
- Microsoft .NET Framework 4.8 on Windows Server 2012
- Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation)
- Microsoft .NET Framework 4.8 on Windows Server 2012 R2
- Microsoft .NET Framework 4.8 on Windows Server 2016 (Server Core installation)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C