CVE-2026-69597
massUse-after-free Elevation of Privilege in Microsoft Windows HTTP.sys
Microsoft's Windows HTTP.sys kernel-mode HTTP protocol stack contains a use-after-free vulnerability (CWE-416) that can be reached over the network. Per Microsoft's scoring, an authorized (low-privilege) attacker, with user interaction and under high-complexity conditions, can trigger the flaw via crafted network traffic that causes the driver to use memory after it has been freed. Successful exploitation allows the attacker to elevate privileges on the target host, with high confidentiality, integrity, and availability impact, likely in a kernel context. Any Windows edition shipping the HTTP.sys driver is potentially affected — most notably servers exposing IIS or other HTTP.sys-based listeners — though the available data does not enumerate specific affected builds. There is no known public proof of concept, the CVE is not in CISA KEV, and EPSS estimates only about a 0.6% chance of exploitation within 30 days.
What to do: Apply Microsoft's current Windows cumulative security update as soon as available, checking Microsoft's advisory for the specific affected builds; prioritize internet-facing Windows Servers running IIS or other HTTP.sys-based listeners. Until patched, restrict authenticated network access to those hosts and monitor for anomalous authenticated HTTP traffic; no workarounds are documented in the available data.
| Microsoft Windows (HTTP.sys kernel HTTP protocol stack) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.