Impact
A heap‑based buffer overflow in the Windows HTTP.sys driver allows an attacker who is already authenticated on a target machine to corrupt internal memory structures. By carefully manipulating these structures, the attacker can modify privileged code paths and ultimately gain higher privileges on the local system. The weakness is a classic memory corruption flaw classified as CWE‑122.
Affected Systems
Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2022; Microsoft Windows Server 2025, including Server Core installations.
Risk and Exploitability
The CVSS score is 7.8, indicating a high severity local privilege escalation risk. The exploit would require an authorized local attacker; no remote exploitation vector is documented. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited publicly known exploitation. Nonetheless, the severity remains significant, so any system running affected versions should consider the risk high.
OpenCVE Enrichment