securityonline.info 8 Sept 2026, 00:30 UTC

Windows HTTP.sys Flaw Enables SYSTEM Access with Public PoC

Windows HTTP.sys Flaw Enables SYSTEM Access with Public PoC
CyberSIXT Evidence Panel Source marked as original reporting
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

SECURITY researchers have disclosed full technical details and a proof‑of‑concept for CVE-2026-62735, a Windows HTTP[.]sys elevation of privilege flaw that scores 7.8 on CVSS v3. The vulnerability centres on an integer overflow in UlpCreateInternalResponseOld within the HTTP[.]sys driver, which can cause a heap overflow in nonpaged pool during header copying.

In the PoC, an oversized HTTP response with around 70,000 custom header entries is sent to the kernel via a specific IOCTL, triggering memory corruption that enables local privilege escalation to SYSTEM. Exploitation is described as requiring local access with low privileges and no user interaction, with a PoC publicly available alongside the details.

Microsoft patched CVE-2026-62735 as part of the August 2026 Patch Tuesday cycle. The advisory lists affected products across Windows 10, Windows 11, and Windows Server editions, spanning versions from Windows 10 1607 through various later builds (including, for example, 10.0.14393.0, 10.0.17763.0, 10.0.19044.0, 10.0.19045.0, 10.0.22631.0, 10.0.26100.0, and others).

The patches are delivered via corresponding KB updates (noted as 10.0.14393.9418, 10.0.17763.9121, 10.0.19044.7663, 10.0.19045.7663, with eight additional entries). The advisory also provides an EPSS of 0.5% over 30 days. At the time of reporting, there were no confirmed exploitation instances, but the publication of the PoC and full technical details increases the risk of local attacks on unpatched systems. Practicable response is to apply the August 2026 security updates promptly and verify build-specific KBs via the official Microsoft advisory.

View full article

Article by CyberSIXT