Impact
Windows HTTP.sys, the kernel‑level HTTP stack in Windows, has an integer overflow or wraparound bug that allows a local, authorized attacker to gain elevated privileges. The flaw is categorized as CWE‑122 and CWE‑190, resulting in a privilege escalation vulnerability.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2 and 26H1; and Microsoft Windows Server releases 2012, 2012 R2, 2016, 2019, 2022 and 2025, both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score is not available, so current exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, a local, authorized attacker can trigger the integer overflow to elevate privileges, making the risk significant on systems lacking timely updates.
OpenCVE Enrichment