ZDI-CAN-29849: ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability
Published Sep 16, 2026
·Updated
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3.
Affected Software
1 affected component
Microsoft Windows
Event History
Sep 16, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
Who is exposed to exploitation?
Affected Microsoft Windows installations are exposed only after an attacker can execute low-privileged code locally on the target system. This is a local privilege-escalation issue, not a standalone remote entry point based on the available information.
2
What access does an attacker need before exploiting this issue?
The attacker must first be able to execute code with low privileges on the target system. The provided information does not identify any additional prerequisites or affected configuration details.