Junglewise Threat Intelligence

CVE-2026-69597: Microsoft Windows HTTP.sys use-after-free privilege escalation

CVE-2026-69597 · Severity: high · CVSS 7.1 · Published 2026-09-08

Vendors: Microsoft.

Executive brief

HTTP.sys is a core Windows kernel driver that handles HTTP traffic for web services and applications. A use-after-free vulnerability allows an attacker with network access to execute malicious code with elevated privileges, potentially compromising the entire system and gaining full control of the affected server.

Technical details

The vulnerability is a use-after-free memory corruption flaw in the Windows HTTP.sys kernel-mode driver. An authorized attacker can trigger the vulnerability over the network by sending specially crafted HTTP requests to exploit a freed memory region, leading to arbitrary code execution in the kernel. The attack requires network connectivity to the target system and an authenticated user context. Successful exploitation results in privilege escalation to SYSTEM level. Microsoft has released patches as part of its regular security updates.

Affected products

  • Microsoft Windows HTTP.sys <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References