CVE-2026-47291

Published Jun 9, 2026

Last updated 14 days ago

Overview

Description
Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2025

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

secure@microsoft.com
CWE-122

Social media

Hype score
Not currently trending
  1. 🚨 June Microsoft Patch Tuesday: 202 vulns fixed 🛠 — 💥 public exploits: HTTP.sys RCE (CVE-2026-47291) + DoS (CVE-2026-49160); notable: BitLocker SFB, Secure Boot SFB, Kernel RCE, DHCP RCE. #PatchTuesday #Microsoft #Windows #Vulristics ➡️ https://t.co/NF1rbexJ2z http

    @leonov_av

    19 Jun 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2026-49160 & CVE-2026-47291 PoC https://t.co/h4IHLCTAYD #CVE_2026_47291_poc #CVE_2026_49160_poc #rce #dos #overflow #microsoft #cve

    @ninjakiii

    16 Jun 2026

    156 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Microsoft、2026年6月定例パッチで史上最多206件の脆弱性を修正-3件のゼロデイや危険な脆弱性含む(CVE-2026-50507,CVE-2026-45586,CVE-2026-47291,CVE-2026-49160) https://t.co/CpGVUObyFk #セキュリティ対策Lab #security #securitynews

    @securityLab_jp

    11 Jun 2026

    114 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Attackers are chaining HTTP.sys exploits (CVE-2026-47291) with Active Directory privilege escalation (CVE-2026-45648) to achieve full domain compromise. TRC analysis shows lateral movement across networks after initial web server breach. Runtime segmentation helps contain

    @aviatrixtrc

    10 Jun 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 Microsoft June 2026 Patch Tuesday just dropped — RECORD 206 CVEs (39 Critical). • CVE-2026-45657 (CVSS 9.8) • CVE-2026-47291 (CVSS 9.8) • CVE-2026-45586 (CVSS 9.8) Plus 3 zero-days (BitLocker bypass + HTTP/2 Bomb). #PatchTuesday #CyberSecurity #CISO https://t.co/v

    @Erwin_Mike_S

    10 Jun 2026

    74 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.