
CVE-2026-21240 Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-21240
Post summary
CVE-2026-21240 is a race condition in Windows HTTP.sys that enables authorized local attackers to elevate privileges; the announcement focuses solely on the vulnerability description.
