Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
CVE-2026-20929 Windows HTTP.sys Elevation of Privilege Vulnerability
Published January 16, 2026
Published January 16, 2026
Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.