CVE-2026-21232
7.8Microsoft · Windows
An untrusted pointer dereference vulnerability exists in the Windows HTTP.sys kernel driver, which may allow an authorized local attacker to elevate privileges.
Executive summary
An untrusted pointer dereference flaw in the Windows HTTP.sys component allows local attackers to achieve privilege escalation, posing a significant risk to system integrity.
Vulnerability
This is an untrusted pointer dereference vulnerability (CWE-822) within the HTTP.sys kernel driver. The flaw requires the attacker to have local access and low-level user privileges to trigger the condition and elevate their permissions.
Business impact
The ability for a local user to escalate privileges to the kernel level threatens the entire security model of the affected machine. With high confidentiality, integrity, and availability impacts as indicated by the CVSS score of 7.8, this vulnerability could lead to total system compromise, data theft, or the installation of persistent malicious software.
Remediation
Immediate Action: Apply the relevant security updates from the Microsoft Security Response Center as outlined in the official update guide.
Proactive Monitoring: Review system event logs for unusual kernel-mode crashes or unexpected privilege escalation attempts associated with the HTTP service.
Compensating Controls: Ensure endpoint detection and response (EDR) solutions are active to identify and block unauthorized attempts to execute code within the kernel context.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the High severity of this privilege escalation vulnerability, organizations should prioritize patching affected Windows 11 endpoints during the next maintenance cycle. Because the vulnerability allows for full control over the local system, timely application of the provided vendor updates is essential to prevent potential exploitation.
More Microsoft CVEs
Sources
- Windows HTTP.sys Elevation of Privilege Vulnerability Vendor advisory