Impact
Improper access control in Windows HTTP.sys enables an authorized attacker to elevate privileges over a network. The vulnerability stems from CWE-284 and can lead to unauthorized escalation of privileges, potentially compromising data confidentiality, system integrity, and availability.
Affected Systems
This vulnerability affects Microsoft Windows client editions Windows 10 versions 1607, 1809, 21H2 11 version 23H2. It also compromises multiple Windows Server editions, including Windows Server 2008 R2 SP1, Windows Server 2008 SP2, Windows Server 2012, 2016, 2019, 2022, and the 23H2 Server Core installation. Both core and non‑core installations are affected.
Risk and Exploitability
With a CVSS score of 7.5 and an EPSS score of 3%, the likelihood of exploitation is low, and it is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector is a network-based exploitation requiring an authorized attacker with access to the target’s HTTP.sys service, typically via crafted HTTP requests within the local or trusted network.
OpenCVE Enrichment