CVE-2026-62741
Windows HTTP.sys Elevation of Privilege Vulnerability
Description
Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-62741 is a Windows privilege-escalation flaw that lets a low-privileged local user gain high privileges on the same PC; most small businesses should patch because it applies to common Windows versions and only requires local access.
CVE-2026-62741 is a local privilege-escalation issue in Windows HTTP.sys caused by an integer underflow/wraparound in the HTTP service; a low-privileged authenticated user can trigger it to escalate to full control on the same machine.
What to do now
- Check whether the affected Windows version is installed and whether your system has pending updates for Windows HTTP components.
- Compare your current Windows build/patch level against the fixed versions listed by Microsoft for CVE-2026-62741.
- Install the Microsoft fix for CVE-2026-62741 (or the latest cumulative update that includes it) on every affected machine.
- If you can’t patch immediately, restrict who has local logon/low-privileged access on the device until updates are applied, and monitor for unusual privilege changes after local logons.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62741 and every CVE in our database. Create a free account — no credit card required.
Create Free Account