Description
Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Elevation of Privilege
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in Windows HTTP.sys that permits an authorized attacker on the network to obtain privileges that exceed those assigned to the attacker. The flaw allows the malicious actor to execute code with elevated privileges, potentially compromising the entire system and any services running on it. The weakness is classified as CWE‑416 and can impact confidentiality, integrity, and availability of the affected systems.

Affected Systems

Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1 as well as Microsoft Windows Server 2025, including Server Core installations, are affected by the flaw.

Risk and Exploitability

With a CVSS score of 7.1, the vulnerability represents a high level of risk. Because the exploit requires an authorized attacker to access the target over a network, the attack vector is inferred to be network‑based. EPSS is not available, so the exploit likelihood cannot be quantified, and the flaw is not listed in the CISA KEV catalog. The use‑after‑free condition could allow local privilege escalation if the attacker controls network traffic to the vulnerable port.

Generated by OpenCVE AI on September 8, 2026 at 22:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for Windows 11 and Windows Server 2025 that addresses CVE‑2026‑69597.
  • Restrict network access to HTTP.sys by configuring firewalls or network segmentation to limit exposure to trusted hosts.
  • Monitor for signs of privilege escalation, such as anomalous process creation or unexpected user account changes, and investigate promptly.

Generated by OpenCVE AI on September 8, 2026 at 22:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
Title Windows HTTP.sys Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 23h2 Windows 11 23h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:35:55.746Z

Reserved: 2026-08-03T21:18:49.124Z

Link: CVE-2026-69597

cve-icon Vulnrichment

Updated: 2026-09-09T09:56:49.124Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:30.237

Modified: 2026-09-21T18:56:13.743

Link: CVE-2026-69597

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:57:48Z

Weaknesses