CVE-2026-21250: Windows HTTP.sys Elevation of Privilege Vulnerability
Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Other sources
Windows HTTP.sys Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.1575Patch KB5077179 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7840Fixed in 10.0.26100.7781Patch KB5077212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7840Fixed in 10.0.26200.7781Patch KB5077212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2149Patch KB5075897 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32370Fixed in 10.0.26100.32313Patch KB5075942
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21250?
CVE-2026-21250 has a high severity rating due to its potential for local privilege escalation.
How do I fix CVE-2026-21250?
To fix CVE-2026-21250, apply the appropriate security patches provided by Microsoft for your specific Windows version.
What operating systems are affected by CVE-2026-21250?
CVE-2026-21250 affects various versions of Microsoft Windows 11 and Windows Server 2025.
Can CVE-2026-21250 be exploited remotely?
No, CVE-2026-21250 requires local access, making it a local privilege escalation vulnerability.
Who is at risk for CVE-2026-21250?
Users and administrators of affected Windows systems are at risk if not patched against CVE-2026-21250.