Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
Plan PatchCVSS 8.8CVE-2026-50444Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A missing authentication check in Windows Server Update Service (WSUS) allows an authenticated, non-administrative user to execute privileged operations over the network. An attacker with a valid user account could bypass authorization controls and execute commands with system-level privileges on the WSUS server or managed clients, such as deploying unauthorized updates or malware across your infrastructure.
What this means
What could happen
An authenticated user without administrative rights could exploit a missing authentication check in WSUS to gain system-level control of your Windows Server or workstation. This could allow an attacker to install patches, malware, or shut down critical systems without detection.
Who's at risk
Windows Server administrators and IT staff managing Windows updates in any organization using WSUS. Affects Windows Server 2016, 2019, 2022, 2025, and Windows 10 systems across all editions. Any environment where WSUS is deployed and reachable from user networks is at risk.
How it could be exploited
An attacker with a valid user account (such as a contractor or compromised network user) connects to the WSUS service over the network and sends commands to a function that lacks proper authentication checks. The attacker bypasses the intended authorization and executes privileged operations, such as pushing malicious updates to all managed devices in your environment.
Prerequisites
- Valid user account credentials on the domain or local network
- Network connectivity to the WSUS server (typically port 8530/8531 or IIS port 80/443)
- User is not already an administrator
Remotely exploitableRequires valid user credentialsLow technical complexity to exploitAffects centralized patch management (could be weaponized to push malware organization-wide)High CVSS score (8.8)
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (11)
11 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/1WORKAROUNDRestrict network access to WSUS ports (8530/8531 or applicable IIS ports) to only authorized client machines and administrators; block access from untrusted network segments
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the 2026-07 security update to all affected Windows Server and Windows 10 systems to patch the WSUS authentication vulnerability
Long-term hardening
0/2HARDENINGVerify that WSUS is running with minimal required privileges; disable unnecessary WSUS roles and features on systems that do not require update management
HARDENINGAudit WSUS access logs and user accounts with network access to WSUS to identify unauthorized activity or dormant accounts that should be disabled
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/061f46e5-1064-4f6a-9666-e93bf1b91517Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.