CVE-2026-50343

HIGH

Microsoft Install Service Elevation of Privilege Vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-50343. PoCs published by Rat5ak.

AI-analyzed exploit summary This repository contains a functional privilege escalation exploit for CVE-2026-50343, leveraging improper registry ACLs on the Microsoft Store InstallService to achieve arbitrary code execution as NT AUTHORITY\SYSTEM from a standard user account. The exploit writes a malicious DLL path to writable registry keys and triggers the service to load it.

Description

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

Exploits (1)

github WORKING POC 1 stars
by Rat5ak · cpoc
https://github.com/Rat5ak/CVE-2026-50343-InstallService-EoP

This repository contains a functional privilege escalation exploit for CVE-2026-50343, leveraging improper registry ACLs on the Microsoft Store InstallService to achieve arbitrary code execution as NT AUTHORITY\SYSTEM from a standard user account. The exploit writes a malicious DLL path to writable registry keys and triggers the service to load it.

Classification
Working Poc 98%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows 11 Pro 25H2 Build 26200.8524 (InstallService)
Auth required
Prerequisites: Standard user account (NT AUTHORITY\INTERACTIVE) · Visual Studio or pre-built DLL for compilation · Target system running vulnerable Windows 11 version
mistral-large-3 · analyzed Jul 16, 2026 Full analysis →

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
Microsoft Install Service Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50343

Scores

CVSS v3 7.8
EPSS 0.0350
EPSS Percentile 87.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (22)
Microsoft/Windows 10 Version 1809 10.0.17763.0 - 10.0.17763.9020
Microsoft/Windows 10 Version 21H2 10.0.19044.0 - 10.0.19044.7548
Microsoft/Windows 10 Version 22H2 10.0.19045.0 - 10.0.19045.7548
Microsoft/Windows 11 Version 24H2 10.0.26100.0 - 10.0.26100.8875
Microsoft/Windows 11 Version 25H2 10.0.26200.0 - 10.0.26200.8875
Microsoft/Windows 11 version 26H1 10.0.28000.0 - 10.0.28000.2269
Microsoft/Windows 11 version 26H1 10.0.28000.0 - 10.0.28000.2525
Microsoft/Windows Server 2019 10.0.17763.0 - 10.0.17763.9020
Microsoft/Windows Server 2019 (Server Core installation) 10.0.17763.0 - 10.0.17763.9020
Microsoft/Windows Server 2022 10.0.20348.0 - 10.0.20348.5386
... and 12 more
Published Jul 14, 2026
Tracked Since Jul 14, 2026