CVE-2026-62735

Published Aug 11, 2026

Last updated 17 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-62735 describes a heap-based buffer overflow vulnerability found within Windows HTTP.sys. This flaw enables an authorized attacker to elevate their privileges on the affected system. The vulnerability specifically impacts the HTTP.sys component of the Windows operating system. An attacker who has already gained some level of authorization can exploit this buffer overflow to achieve higher access rights locally.

Description
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2025

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-122

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.