Junglewise Threat Intelligence

CVE-2026-20929: Microsoft Windows HTTP.sys privilege escalation

CVE-2026-20929 · Severity: high · CVSS 7.5 · Published 2026-01-13

Technologies: Microsoft Windows 10, Microsoft Windows Server 2008, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows component responsible for handling web traffic (HTTP.sys). This flaw could allow a user who already has basic access to the network to gain higher-level administrative privileges. If exploited, an attacker could potentially take full control of the affected system, leading to unauthorized data access or service disruption.

Technical details

An improper access control vulnerability (CWE-284) exists in the Windows HTTP protocol stack (HTTP.sys). The vulnerability allows an authenticated attacker with low-level privileges to elevate their permissions over the network. Exploitation requires the attacker to have existing network access and authorized credentials, and the attack complexity is rated as high, suggesting specific environmental conditions or timing may be required. Successful exploitation grants the attacker high impact across confidentiality, integrity, and availability. Microsoft has released security updates to address this issue across various versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 Version 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 Version 22H3, 23H2
  • Microsoft Windows Server 2008 Service Pack 2, R2 Service Pack 1

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: patched

References

Related threats