CVE-2026-62735PoC(microsoft / windows_10_1607)

CRITICALCVSS 7.8 · HIGH

Exploitation ongoing with high activity in latest observed window (6 mentions)

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

8.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-190

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 9 signals
  • General: 2 classified signals
  • Peaked at 6 mentions on most recent observed day (2026-09-08)
  • 11 total mentions across 4 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 13 products

Deep dive

Activity timeline11 mentions / 4d
02356Mentions · 2026-08-12: 1Mentions · 2026-09-01: 2Mentions · 2026-09-07: 2Mentions · 2026-09-08: 6PoC Mentioned / Linked · 2026-09-07: 2PoC Mentioned / Linked · 2026-09-08: 5Exploit Tool / Code · 2026-09-07: 2Exploit Tool / Code · 2026-09-08: 2Active Exploitation · 2026-09-07: 1Patch / Workaround · 2026-08-12: 1Patch / Workaround · 2026-09-08: 4Technical Details · 2026-08-12: 1Technical Details · 2026-09-01: 2Technical Details · 2026-09-07: 2Technical Details · 2026-09-08: 408-1209-0109-0709-08
Signal classification5 categories
PoC
654.5%
General
218.2%
Patch
19.1%
Exploit
19.1%
Disclosure
19.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-08-121
Patch1
2026-09-012
General2
2026-09-072
Exploit1PoC1
2026-09-086
Disclosure1PoC5
Full discourse11 posts
  • Nicolas Krassas@Dinosn
    General

    CVE-2026-62735 — Windows HTTP.sys Elevation of Privilege. https://hackmd.io/@nhh/Hy6Oem7_Me

    Post summary

    The snippet merely announces the CVE and links to an external note, providing minimal technical context.

    13801437312.9K
    161.5K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-62735 PT ID: PT-2026-70496 Vendor: Microsoft Product: Windows 10 Version 1607 Description: Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-70496 • https://github.com/cli0xfa/simple-krw-vuln/tree/main/CVE-2026-62735

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑62735, demonstrating a heap‑based buffer overflow in Windows HTTP.sys that can lead to local privilege escalation on Windows 10, has been released and is available via a GitHub repository.

    09044265.9K
    3.6K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Exploit

    🔴 Windows HTTP.sys için CVE-2026-62735'e ait çalışan PoC/Exploit ortaya çıktı. Microsoft Windows'ta 7.8 High seviyeli Local Privilege Escalation açığı. Düşük yetkili bir yerel kullanıcı, HTTP.sys'deki heap/integer overflow zincirini kullanarak SYSTEM seviyesine çıkabiliyor. Windows Server 2016 dahil birçok Windows sürümü etkileniyor. Public exploit nedeniyle özellikle eski Windows Server sistemlerinin güncel build seviyeleri kontrol edilmeli. PoC: https://github.com/cli0xfa/simple-krw-vuln/tree/main/CVE-2026-62735

    Post summary

    A functional exploit/PoC for CVE-2026-62735 has been released, enabling local privilege escalation on multiple Windows Server versions; users should verify build levels.

    0401581.3K
    2.4K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    A Windows HTTP.sys vulnerability, CVE-2026-62735 (CVSS 7.8), now has public details and a PoC. It escalates local users to SYSTEM. Patch now. #Windows #HTTPsys #CVE202662735 #PrivilegeEscalation #Pwn2Own #SYSTEM #Infosec #PoC https://securityonline.info/windows-http-sys-cve-2026-62735/ https://t.co/0gnt1SnDu4

    Post summary

    Windows HTTP.sys CVE-2026-62735 is now publicly documented with a PoC that allows local users to elevate to SYSTEM; a vendor patch has been released.

    01022482
    12.9K followersView on X
  • kokumօtօ@__kokumoto
    PoC

    権限昇格脆弱性WindowsのHTTP.sysにおけるCVE-2026-62735(CVSSスコア7.8)に対応するPoC(攻撃の概念実証コード)が公表された。8月の定例更新で修正されていたもの。 https://securityonline.info/windows-http-sys-cve-2026-62735/

    Post summary

    A PoC for CVE-2026-62735, a privilege‑escalation vulnerability in Windows HTTP.sys, has been published and the issue was patched in the August update.

    00030861
    7.8K followersView on X
  • キタきつね@foxbook
    PoC

    Windows HTTP.sys CVE-2026-62735: PoC Exploit Released for Privilege Escalation Flaw(Windows HTTP.sysの権限昇格脆弱性、CVE-2026-62735のPoC Exploitが公開) #SecurityOnline (Sep 7) https://securityonline.info/windows-http-sys-cve-2026-62735/

    Post summary

    A PoC exploit for the Windows HTTP.sys privilege‑escalation flaw CVE-2026-62735 has been publicly released, but no specific exploitation details, patch information, or evidence of real‑world attacks are provided.

    00001318
    5.0K followersView on X
  • moton@moton
    PoC

    CVE-2026-62735: Windows Elevation of Privilege PoC Goes Public - https://securityonline.info/windows-http-sys-cve-2026-62735/

    Post summary

    The post announces that a Proof of Concept for the Windows elevation‑of‑privilege vulnerability CVE‑2026‑62735 has been released publicly, without detailing exploitation code or mitigation.

    0000096
    756 followersView on X
  • NEXSIGHT@NEXSIGHTNEWS
    PoC

    WindowsのHTTP.sysに権限昇格の脆弱性 — CVE-2026-62735、PoC公開でSYSTEM奪取のおそれ、8月更新で修正済み https://cyber.nexsight.co/articles/2026/09/08/windows-httpsys-cve-2026-62735-privilege-escalation-poc-2026-09-08/

    Post summary

    CVE‑2026‑62735 is a privilege‑escalation flaw in Windows HTTP.sys; a PoC has been published and a patch was released in August.

    0000077
    65 followersView on X
  • HackProve@hackprove_
    Disclosure

    【Vulnerability Disclosure | CVE Spotlight】 ⚠️ Critical Windows HTTP.sys Elevation of Privilege Vulnerability (CVE‑2026‑62735) HTTP.sys is a Windows kernel‑mode HTTP stack driver that powers IIS and other services relying on the Windows HTTP Server API. The flaw stems from an integer overflow and defective heap buffer boundary validation. A local attacker with low‑level privileges can trigger a heap buffer overflow through maliciously crafted operations, achieving arbitrary code execution under a high‑privileged context. Affected Versions: ✅ Windows 10 1607 (Build < 14393.9418) 1809 (Build < 17763.9121) 21H2 (Build < 19044.7663) 22H2 (Build < 19045.7663) ✅ Windows 11 23H2 (Build < 22631.7517) 24H2 (Standard < 26100.9168 / Hotpatch < 26100.9106) 25H2 (Standard < 26200.9168 / Hotpatch < 26200.9106) 26H1 (Build < 28000.2704) ✅ Windows Server 2012 (Build < 6.2.9200.26280) 2012 R2 (Build < 6.3.9600.23338) 2016 (Build < 14393.9418) 2019 (Build < 17763.9121) 2022 (Standard < 20348.5499 / Hotpatch < 20348.5440) 2025 (Standard < 26100.33296 / Hotpatch < 26100.33222) Mitigation: Patch now via Windows Update or Microsoft official advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62735 #HackProve #Cybersecurity #CVE202662735 #WindowsSecurity

    Post summary

    Microsoft publicly discloses CVE‑2026‑62735, a Windows HTTP.sys privilege‑escalation flaw that allows local attackers to achieve arbitrary code execution, and urges affected users to apply the available patch via Windows Update or the MSRC advisory.

    00000174
    1.5K followersView on X
  • ✪ 𝕱𝖆𝖍𝖆𝖉@fad_777
    General

    ثغرات رفع الصلاحيات في Windows HTTP.sys تستحق أولوية خاصة لأنها تمس مكوّناً أساسياً في معالجة طلبات HTTP داخل Windows. CVE-2026-62735 يشير إلى Elevation of Privilege، وهذا النوع من الثغرات قد يغيّر مستوى المخاطر عند وجوده على أنظمة حساسة أو خوادم معرضة. القيمة التقنية هنا ليست في اسم الثغرة فقط، بل في ربطها بإدارة الأصول، تقييم التعرض، ومراجعة مسار التصحيح ضمن برنامج إدارة الثغرات. عملياً، يجب تتبع النشرة الرسمية، تحديد الأنظمة المتأثرة، وترتيب أولوية المعالجة وفق مستوى التعرض ودور النظام. CVE-2026-62735 highlights an Elevation of Privilege issue in Windows HTTP.sys, a Windows component tied to HTTP request handling. This matters because privilege escalation vulnerabilities can become more serious when they affect systems that already process network-facing workloads or sensitive services. The practical value is in vulnerability management: map affected Windows assets, validate exposure, monitor the official advisory, and prioritize remediation based on system criticality. For security teams, the key is not only identifying the CVE, but understanding where HTTP.sys exists in the environment and how quickly affected systems can be addressed. https://hackmd.io/@nhh/Hy6Oem7_Me #CVE #WindowsSecurity #VulnerabilityManagement #leab26 #ليب26

    Post summary

    The post highlights CVE‑2026‑62735 as an elevation‑of‑privilege flaw in Windows HTTP.sys and stresses its importance for vulnerability management, but it offers no PoC, exploit code, active exploitation evidence, nor patch details.

    0000090
    86 followersView on X
  • Windows Forum@windowsforum
    Patch

    🛡️ CVE-2026-62735 hits Windows HTTP.sys with privilege escalation, but Microsoft left the risk details fuzzy. Patch August updates now—because “we’ll rank it later” is not a security strategy. https://windowsforum.com/security-alerts.84/cve-2026-62735-patch-windows-http-sys-privilege-escalation.442610/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #PatchManagement #HttpSys #WindowsSecurityUpdates #Cve202662735 https://t.co/TS5hSBIIEF

    Post summary

    The tweet announces that CVE-2026-62735 causes privilege escalation in Windows HTTP.sys and that Microsoft has issued August patch updates, without providing detailed exploit information or claiming active exploitation.

    0000036
    1.3K followersView on X
CPE platform detail24 entries

24 of 24 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2025---

Explore more