CVE-2026-50488
Microsoft Windows 11 Version 24H2, Windows 11 Version 25H2, Windows Server 2025
Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate privileges locally.
- CVSS
- 7.8
- EPSS
- 0.23% 14.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.15