Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
2026-02-10T18:16:26.670
2026-02-11T19:49:34.573
Analyzed
CVSSv3.1: 7.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | microsoft | windows_11_24h2 | < 10.0.26100.7781 | Yes |
| Operating System | microsoft | windows_11_24h2 | < 10.0.26100.7781 | Yes |
| Operating System | microsoft | windows_11_25h2 | < 10.0.26200.7781 | Yes |
| Operating System | microsoft | windows_11_25h2 | < 10.0.26200.7781 | Yes |
| Operating System | microsoft | windows_server_2022_23h2 | < 10.0.25398.2149 | Yes |
| Operating System | microsoft | windows_server_2025 | < 10.0.26100.32313 | Yes |