AI description
CVE-2026-62735 describes a heap-based buffer overflow vulnerability found within Windows HTTP.sys. This flaw enables an authorized attacker to elevate their privileges on the affected system. The vulnerability specifically impacts the HTTP.sys component of the Windows operating system. An attacker who has already gained some level of authorization can exploit this buffer overflow to achieve higher access rights locally.
- Description
- Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2025
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- secure@microsoft.com
- CWE-122
- Hype score
- Not currently trending
CVE-2026-62735: Windows Elevation of Privilege PoC Goes Public - https://t.co/ZTA3vZkMZR
@moton
8 Sept 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Windows HTTP.sys CVE-2026-62735: PoC Exploit Released for Privilege Escalation Flaw(Windows HTTP.sysの権限昇格脆弱性、CVE-2026-62735のPoC Exploitが公開) #SecurityOnline (Sep 7) https://t.co/zIRdTJNPqc
@foxbook
8 Sept 2026
294 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
A PoC/exploit has been discovered for vulnerability CVE-2026-62735 PT ID: PT-2026-70496 Vendor: Microsoft Product: Windows 10 Version 1607 Description: Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. References: •
@ptdbugs
7 Sept 2026
325 Impressions
1 Retweet
4 Likes
2 Bookmarks
0 Replies
0 Quotes
ثغرات رفع الصلاحيات في Windows HTTP.sys تستحق أولوية خاصة لأنها تمس مكوّناً أساسياً في معالجة طلبات HTTP داخل Windows. CVE-2026-62735 يشير إلى Elevation of Privilege، وهذا النوع من الث
@fad_777
1 Sept 2026
61 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-62735 — Windows HTTP.sys Elevation of Privilege. https://t.co/QvwLnZqsnn
@Dinosn
1 Sept 2026
3075 Impressions
12 Retweets
41 Likes
20 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "14FF7EDA-F43B-4BB4-BC6C-7EFE15382EEB",
"versionEndExcluding": "10.0.14393.9418",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "CB3EDBCC-9F4E-49F2-9701-67D2C1F7B47A",
"versionEndExcluding": "10.0.14393.9418",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "3B36E37E-C661-4F5B-BFAB-8DE7EA3BBF5A",
"versionEndExcluding": "10.0.17763.9115",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "490C0819-7717-4869-B85C-2A218E7C50B2",
"versionEndExcluding": "10.0.17763.9115",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "5ED5CE2C-875F-4A90-8D6A-D2D6C27079F4",
"versionEndExcluding": "10.0.19044.7663",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "CB6135C0-63D0-4B62-B886-34F37630951D",
"versionEndExcluding": "10.0.19044.7663",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "BCDC9886-210A-4CB1-96F6-8688D299CDB2",
"versionEndExcluding": "10.0.19044.7663",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "FDE9156A-B904-49C2-9935-6FD1697295BA",
"versionEndExcluding": "10.0.19045.7663",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "8436A957-24ED-43B6-B0C0-C32AE5146E98",
"versionEndExcluding": "10.0.19045.7663",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "341F984B-9949-4EF2-B902-D9CF093F32DD",
"versionEndExcluding": "10.0.19045.7663",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "FF6AD596-A1A0-4090-B1F0-02B66BBFB2B4",
"versionEndExcluding": "10.0.22631.7517",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "56C435FD-7DB3-4A08-B3E1-2446AE91BCB3",
"versionEndExcluding": "10.0.22631.7517",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "630926CB-2963-456C-B212-B71429425036",
"versionEndExcluding": "10.0.26100.9106",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "E9234EA9-5877-4256-B462-6D28438030CB",
"versionEndExcluding": "10.0.26100.9106",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "809B41FD-A2F1-4574-9E30-C409199FDDD2",
"versionEndExcluding": "10.0.26200.9106",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "657B3118-ED3F-45E7-9A46-6DE306CF2C14",
"versionEndExcluding": "10.0.26200.9106",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "BE88CAB4-881C-4300-AA9F-0E3F59371786",
"versionEndExcluding": "10.0.28000.2704",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "DBF52600-4F74-4C60-8792-0BB6CA65823A",
"versionEndExcluding": "10.0.28000.2704",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
"matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
"matchCriteriaId": "14EEFCD3-C815-4CBE-99AB-6AFB40EF2FE9",
"versionEndExcluding": "10.0.14393.9418",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7877A816-4EF3-4DA9-81F6-DF77056F329B",
"versionEndExcluding": "10.0.17763.9115",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8EBC7E47-4744-4802-B04C-869AA63985A5",
"versionEndExcluding": "10.0.20348.5440",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
"matchCriteriaId": "48C0EB1A-5EC0-4916-A812-08E16FEB040A",
"versionEndExcluding": "10.0.26100.33222",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]