• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-62735: local privilege escalation in Microsoft Windows 10 Version 1607

A local, authorized user can elevate privileges on Windows systems via a heap-based buffer overflow in HTTP.sys (CVE-2026-62735). Affects multiple Windows branches including Windows 10 Version 1607 (10.0.14393 before 10.0.14393.9418), 1809 (10.0.17763 before 10.0.17763.9121), 21H2, 22H2, several Windows 11 releases (fixed in their listed builds), and Windows Server 2012 (6.2.9200 before 6.2.9200.26280); an attacker requires a local account with low privileges to trigger the flaw (no user interaction).

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
7.8HIGH
EPSS
0.00333
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Patch urgently: public exploit code is available, so prioritize applying the vendor updates listed below for affected builds or otherwise restrict and monitor local access to vulnerable hosts.

What is CVE-2026-62735?

A local, authorized user can elevate privileges on Windows systems via a heap-based buffer overflow in HTTP.sys (CVE-2026-62735). Affects multiple Windows branches including Windows 10 Version 1607 (10.0.14393 before 10.0.14393.9418), 1809 (10.0.17763 before 10.0.17763.9121), 21H2, 22H2, several Windows 11 releases (fixed in their listed builds), and Windows Server 2012 (6.2.9200 before 6.2.9200.26280); an attacker requires a local account with low privileges to trigger the flaw (no user interaction). The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.941810.0.14393.9418
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.912110.0.17763.9121
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.766310.0.19044.7663
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.766310.0.19045.7663
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.751710.0.22631.7517
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.751710.0.22631.7517
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.916810.0.26100.9168
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.916810.0.26200.9168
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.270410.0.28000.2704
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.262806.2.9200.26280

Is CVE-2026-62735 being exploited?

Public exploit code is available.

How to fix CVE-2026-62735

  1. Install the Microsoft updates that include the listed fixed builds (for example 10.0.14393.9418, 10.0.17763.9121, 10.0.19044.7663, 10.0.19045.7663, 10.0.22631.7517, 10.0.26100.9168, 10.0.26200.9168, 10.0.28000.2704, 6.2.9200.26280).
  2. Restrict local account access and remove unnecessary interactive logons on internet-facing or multi-user systems.
  3. Monitor event logs and endpoint telemetry for suspicious local process creation or privilege escalation attempts.
  4. Follow Microsoft guidance and apply vendor-provided mitigations if you cannot immediately update.

Frequently asked questions

Is CVE-2026-62735 being actively exploited?

Public exploit code for CVE-2026-62735 is available.

Which Windows versions are affected by CVE-2026-62735?

Windows 10 Version 1607 and 1809 branches, multiple Windows 10/11 releases listed in the vendor advisory, and Windows Server 2012 are affected; each branch has specific build ranges that are vulnerable as detailed above.

Is there a patch for CVE-2026-62735?

Yes. Microsoft published fixes; vulnerable branches have corresponding fixed builds such as 10.0.14393.9418, 10.0.17763.9121, 10.0.19044.7663, 10.0.19045.7663, 10.0.22631.7517, 10.0.26100.9168, 10.0.26200.9168, 10.0.28000.2704, and 6.2.9200.26280.

Does CVE-2026-62735 require authentication?

Yes. The vulnerability requires a local, authorized account (low-privileged) on the affected Windows systems to trigger the heap-based overflow in HTTP.sys.

References