Heap-Based Buffer Overflow in Windows HTTP.sys Affects Microsoft Products
CVE-2026-62735

7.8HIGH

Key Information:

Badges

πŸ“ˆ Score: 896πŸ‘Ύ Exploit Exists🟑 Public PoC

What is CVE-2026-62735?

CVE-2026-62735 is a security vulnerability identified in Windows HTTP.sys, a core component responsible for handling HTTP communications in Microsoft products. This vulnerability is classified as a heap-based buffer overflow, which occurs when data exceeds the buffer storage capacity, leading to potential corruption of adjacent memory. An attacker with local access can exploit this weakness to escalate privileges, potentially gaining higher levels of control over the affected systems. This elevation of privileges could result in unauthorized access to sensitive data, manipulation of system operations, and the potential for further exploitation of the system, which poses a significant risk to organizational security.

Potential impact of CVE-2026-62735

  1. Privilege Escalation: The primary impact of this vulnerability is the ability for an authorized attacker to gain elevated privileges, allowing them to execute commands and access resources that are normally restricted. This could lead to unauthorized data manipulation or extraction.

  2. Increased Attack Surface: The successful exploitation of this vulnerability could enable attackers to install malicious software or create backdoors, thereby expanding the attack surface of the organization. Such capabilities can facilitate further intrusions or system compromises.

  3. System Integrity Compromise: Organizations could face a significant risk to the integrity of their systems and data due to the potential unauthorized actions made possible by this vulnerability. This can lead to data breaches, loss of sensitive information, and disruption of critical business operations.

Affected Version(s)

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9418

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.9121

Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7663

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.