Integer Overflow Vulnerability in Windows HTTP.sys by Microsoft
CVE-2026-47291

9.8CRITICAL

Key Information:

Badges

๐Ÿ‘พ Exploit Exists๐Ÿ“ฐ News Worthy

What is CVE-2026-47291?

An integer overflow vulnerability exists in Windows HTTP.sys, which can be exploited by an unauthorized attacker to execute arbitrary code over a network. This flaw can compromise system integrity and potentially allow for unauthorized access or control. It is crucial for users to apply the latest security updates and patches to safeguard their systems against this risk.

Affected Version(s)

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9234

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8880

Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7417

News Articles

Blame AI: Patch Tuesday Hits Record 206 CVEs

Voluminous patch updates could soon be the norm, as artificial intelligence accelerates the speed and scale of vulnerability discovery.

2 weeks ago

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • ๐Ÿ“ฐ

    First article discovered by Dark Reading

  • Vulnerability published

  • Vulnerability Reserved

.