CVE-2026-50367CWE-118CWE-822

Windows Sensor Data Service Elevation of Privilege Vulnerability

High · published July 14, 2026

CVSS v3.1
7.8
EPSS
0%
Percentile
26.0
In the wild
Unconfirmed
What it is

Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CVSS v4.0
Not supplied
EPSS
0.00333 · 26.0th percentile
Weaknesses
CWE-118 · Incorrect Access of Indexable Resource ('Range Error'); CWE-822 · Untrusted Pointer Dereference
Published
2026-07-14T17:07Z
EPSS history
Timeline
  • 14 JUL 17:07Z
    Windows Sensor Data Service Elevation of Privilege Vulnerability
    cvelistv5