PT-2026-70496 · Microsoft · Windows

CVE-2026-62735

·

Published

2026-08-11

·

Updated

2026-09-08

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows HTTP.sys (affected versions not specified)
Description A heap-based buffer overflow exists in the Windows HTTP.sys driver. This issue occurs due to an integer overflow, which can be exploited by an authorized attacker to elevate privileges locally on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

LPE

Heap Based Buffer Overflow

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11449
CVE-2026-62735
ZDI-26-536

Affected Products

Windows