Executive brief
A security vulnerability exists in the Windows component responsible for handling web traffic (HTTP.sys). An attacker with local access to a system could exploit this flaw to view sensitive information that should normally be protected. While this does not allow for remote control of the computer, it could lead to the exposure of confidential data or system memory contents.
Technical details
This vulnerability is classified as an out-of-bounds read (CWE-125) within the Windows HTTP protocol stack (HTTP.sys). The flaw occurs when the driver improperly validates memory buffers, allowing an attacker to read data beyond the intended memory range. The attack vector is local, meaning an attacker must have the ability to execute code on the target system, though no special privileges or user interaction are required. Successful exploitation results in information disclosure, potentially revealing kernel memory or other sensitive system data. Microsoft has released security updates to address this issue across affected versions of Windows 11 and Windows Server 2025.
Affected products
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory