CVE-2026-50472 — Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability
Executive Summary
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 1607 for 32-bit Systems | 5120418 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5120418 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5120238 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5120238 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5120240 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5120240 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5120994 (Security Hotpatch Update) 5121003 (Security Update) Important Elevation of Privilege 5101650 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9106 10.0.26100.9168 Yes None Windows 11 Version 24H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9168 10.0.26000.9106 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 25H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 26H1 for ARM64-based Systems | 5121000 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 26H1 for x64-based Systems | 5121000 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 | 5120386 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 (Server Core installation) | 5120386 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 | 5120385 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5120385 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 | 5120418 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 (Server Core installation) | 5120418 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 5120238 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 5120238 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5120418 |
Security Update | Yes |
5120238 |
Security Update | Yes |
5120249 |
Security Update | Yes |
5120240 |
Security Update | Yes |
5121000 |
Security Update | Yes |
5120386 |
Monthly Rollup | Yes |
5120385 |
Monthly Rollup | Yes |
Patch Diff
Heap-based buffer overflow (CWE-122) via a race in the Windows LUA File Virtualization filter driver luafv.sys FileId-table node update, local EoP to SYSTEM (AC:H race). LUAFV virtualizes file access for legacy (LUA) apps and maintains a table of FileId nodes that cache per-file state including a path/name UNICODE_STRING (stored at node+0x50). UpdateTableNode refreshes a node from current file information (GetFileInformation) and, on failure, removed the node. PRE: the node-update path was insufficiently synchronized against concurrent update/removal of the same node, so a racing operation could update or reallocate the node's cached buffer while another path used it - a race leading to a heap buffer overflow of the node's allocation. Because luafv runs in the kernel and the virtualization path is reachable by a local user, and exploitation requires winning the race (AC:H), the overflow is a local EoP-to-SYSTEM primitive. Diff of luafv.sys 10.0.26100.8972 -> .9168 (Aug 11 2026, KB5121003) confirms the fix: gated behind CFR flag Feature_285200698, UpdateTableNode adds a name-match check (RtlCompareUnicodeString against the node name at +0x50) and gates the RemoveFileIdTableNode call so a node is not removed/reused out from under a concurrent update, and routes the node allocation through the LuafvAllocatePool wrapper instead of raw ExAllocatePool2. Note: UpdateTableNode is confirmed code-changed under Feature_285200698 with the added name-match/gated-removal/allocator changes; the exact overflowing write is not cleanly isolable in this race-hardening restructure, so the mechanism is stated per the CWE-122 + AC:H classification and the observed changes.
| Function | Address | Change | Note |
|---|---|---|---|
UpdateTableNode |
code change |
code (race-hardened FileId-table node update, CFR-gated) | Pre: node update/removal on the FileId table node (name at +0x50) insufficiently synchronized -> racing update/realloc heap overflow. Post (Feature_285200698): adds RtlCompareUnicodeString name-match against node+0x50, gates the RemoveFileIdTableNode call, and allocates via LuafvAllocatePool instead of ExAllocatePool2. |
LuafvAllocatePool |
call change |
now used for node allocation | UpdateTableNode now routes the node allocation through the LuafvAllocatePool wrapper (replacing a direct ExAllocatePool2). |
RemoveFileIdTableNode |
call change |
invocation gated | Its removal call from UpdateTableNode is now conditioned under Feature_285200698 to avoid removing a node concurrently in use. |
Feature_285200698 |
gate |
added (CFR gate) | CFR flag gating the race-hardened node update; the original path still ships when disabled. (Feature_3287483706 / Feature_3614170424 also present in this update.) |
Attack Path
A concurrent update of a LUAFV FileId-table node races the node's removal/reallocation, overflowing its cached buffer
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.