CVE-2026-21250Disclosure(microsoft / windows_11_24h2)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for microsoft windows_11_24h2 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-822

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_24h2
  • windows_11_25h2
  • windows_server_2022_23h2
  • windows_server_2025

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-10); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
windows_11_24h2windows_11_25h2windows_server_2022_23h2windows_server_2025

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-10: 1Mentions · 2026-05-04: 1PoC Mentioned / Linked · 2026-05-04: 1Exploit Tool / Code · 2026-05-04: 1Technical Details · 2026-02-10: 1Technical Details · 2026-05-04: 102-1005-04
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-101
Disclosure1
2026-05-041
PoC1
Full discourse2 posts
  • DarkRelay Security Labs@darkrelaylabs
    PoC

    Windows 11 24H2 LPE vulnerability (CVE-2026-21250) → Local privilege escalation → Potential SYSTEM access Exploit PoC is public 👇 https://www.exploit-db.com/exploits/52546 Patch or mitigate ASAP. #CyberSecurity #Infosec #Pentesting

    Post summary

    The post announces a public PoC for CVE-2026-21250, a local privilege escalation flaw in Windows 11 24H2 that could grant SYSTEM access, but does not mention active exploitation or an official patch.

    121069534.3K
    146 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21250 Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-21250

    Post summary

    The text discloses a privilege‑elevation vulnerability in Windows HTTP.sys (CVE‑2026‑21250) caused by an untrusted pointer dereference, but no PoC, exploit, or patch information is included.

    00010155
    56.5K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more