ZeroHour

CVE-2026-69597

mass

Use-after-free Elevation of Privilege in Microsoft Windows HTTP.sys

CVSS 3.1
7.1 high
EPSS
<1%p45
Published
()
Modified
AI analysis

Microsoft's Windows HTTP.sys kernel-mode HTTP protocol stack contains a use-after-free vulnerability (CWE-416) that can be reached over the network. Per Microsoft's scoring, an authorized (low-privilege) attacker, with user interaction and under high-complexity conditions, can trigger the flaw via crafted network traffic that causes the driver to use memory after it has been freed. Successful exploitation allows the attacker to elevate privileges on the target host, with high confidentiality, integrity, and availability impact, likely in a kernel context. Any Windows edition shipping the HTTP.sys driver is potentially affected — most notably servers exposing IIS or other HTTP.sys-based listeners — though the available data does not enumerate specific affected builds. There is no known public proof of concept, the CVE is not in CISA KEV, and EPSS estimates only about a 0.6% chance of exploitation within 30 days.

What to do: Apply Microsoft's current Windows cumulative security update as soon as available, checking Microsoft's advisory for the specific affected builds; prioritize internet-facing Windows Servers running IIS or other HTTP.sys-based listeners. Until patched, restrict authenticated network access to those hosts and monitor for anomalous authenticated HTTP traffic; no workarounds are documented in the available data.

Affected
Microsoft Windows (HTTP.sys kernel HTTP protocol stack)
Estimated exposure
masshundreds of millions of Windows installations (HTTP.sys ships with Windows; millions of internet-exposed IIS/HTTP.sys endpoints) — HTTP.sys is a core component present on effectively all modern Windows client and server editions (Microsoft has cited more than 1.4 billion active Windows devices), and public internet scans show millions of exposed IIS/HTTP.sys HTTP…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.