Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Feb 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft windows 11 22h3
Microsoft windows 11 26h1 Microsoft windows Server 2022, 23h2 Edition (server Core Installation) Microsoft windows Server 2025 (server Core Installation) |
|
| Vendors & Products |
Microsoft windows 11 22h3
Microsoft windows 11 26h1 Microsoft windows Server 2022, 23h2 Edition (server Core Installation) Microsoft windows Server 2025 (server Core Installation) |
Wed, 11 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft windows 11 23h2
Microsoft windows 11 24h2 Microsoft windows 11 25h2 Microsoft windows Server 2022 23h2 |
|
| CPEs | cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft windows 11 23h2
Microsoft windows 11 24h2 Microsoft windows 11 25h2 Microsoft windows Server 2022 23h2 |
Tue, 10 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | |
| Title | Windows HTTP.sys Elevation of Privilege Vulnerability | |
| First Time appeared |
Microsoft
Microsoft windows 11 23h2 Microsoft windows 11 24h2 Microsoft windows 11 25h2 Microsoft windows 11 26h1 Microsoft windows Server 2025 Microsoft windows Server 23h2 |
|
| Weaknesses | CWE-822 | |
| CPEs | cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_23h2:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft windows 11 23h2 Microsoft windows 11 24h2 Microsoft windows 11 25h2 Microsoft windows 11 26h1 Microsoft windows Server 2025 Microsoft windows Server 23h2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-02-12T19:11:44.808Z
Reserved: 2025-12-11T21:02:05.734Z
Link: CVE-2026-21232
Updated: 2026-02-10T21:21:59.190Z
Status : Analyzed
Published: 2026-02-10T18:16:23.770
Modified: 2026-02-11T21:12:11.617
Link: CVE-2026-21232
No data.