SB2026011371 - Privilege escalation in Microsoft Windows HTTP.sys 



SB2026011371 - Privilege escalation in Microsoft Windows HTTP.sys

Published: January 13, 2026

Security Bulletin ID SB2026011371
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper access control (CVE-ID: CVE-2026-20929)

The vulnerability allows a remote user to compromise the affected system.

The vulnerability exists due to improper access restrictions Windows HTTP.sys. A remote user can send specially crafted packets to the system and execute arbitrary code with SYSTEM privileges. 

Note, successful exploitation of the vulnerability requires an Service Principal Name (SPN) that is registered to an account that no longer exists or is not in use.

Remediation

Install update from vendor's website.