Executive brief
A vulnerability in the Windows component responsible for handling web traffic (HTTP.sys) could allow an attacker to crash a computer or server over the network. This component is essential for hosting websites and web services on Windows systems. An exploit would result in a denial-of-service, potentially taking down corporate websites or internal applications until the system is restarted.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Windows HTTP protocol stack (HTTP.sys). The flaw is triggered when the component improperly handles specially crafted HTTP requests. An unauthenticated attacker can exploit this over the network without user interaction to cause a system crash (BSOD), resulting in a denial-of-service. The vulnerability affects multiple versions of Windows 11 and Windows Server, including 2022 and 2025. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2, 26H1
- Microsoft Windows Server 2022 including 23H2 Edition
- Microsoft Windows Server 2025 including Server Core installation
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory