Executive brief
A security vulnerability has been identified in the Windows component responsible for handling web traffic (HTTP.sys). This flaw could allow a user who already has basic access to the network to gain higher-level administrative privileges. If exploited, an attacker could potentially take full control of the affected system, leading to unauthorized data access or service disruption.
Technical details
An improper access control vulnerability (CWE-284) exists in the Windows HTTP protocol stack (HTTP.sys). The vulnerability allows an authenticated attacker with low-level privileges to elevate their permissions over the network. Exploitation requires the attacker to have existing network access and authorized credentials, and the attack complexity is rated as high, suggesting specific environmental conditions or timing may be required. Successful exploitation grants the attacker high impact across confidentiality, integrity, and availability. Microsoft has released security updates to address this issue across various versions of Windows and Windows Server.
Affected products
- Microsoft Windows 10 Version 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 Version 22H3, 23H2
- Microsoft Windows Server 2008 Service Pack 2, R2 Service Pack 1
Timeline
- 2026-01-13: disclosed
- 2026-01-13: patched