Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-21250 — Technical documentation and resources for CVE-2026-21250, a Windows HTTP.sys local privilege escalation vulnerability, including affected versions, CVSS details, and mitigation guidance. | Kitploit
Tools/GitHubGitHub/kaleth4/cve-2026-21250
Privilege EscalationVulnerability AnalysisExploitationLearning & EducationCurated Resources
GitHubkaleth4/cve-2026-21250

CVE-2026-21250

Technical documentation and resources for CVE-2026-21250, a Windows HTTP.sys local privilege escalation vulnerability, including affected versions, CVSS details, and mitigation guidance.

View Repository
3 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-21250: Windows HTTP.sys Local Privilege Escalation

Windows 11 24H2 - Local Privilege Escalation

🚨 Technical analysis and resources for vulnerability CVE-2026-21250 Windows 11 24H2 / 25H2 - Windows Server 2022/2025


This repository contains technical documentation and resources for studying vulnerability CVE-2026-21250, an untrusted pointer dereference flaw in the Windows HTTP.sys driver that allows local privilege escalation (LPE).

📝 Description

The vulnerability allows an attacker with low privileges and local access to the system to execute code with elevated privileges by exploiting improper pointer handling in the HTTP.sys component.

📊 Technical Details (NVD)

  • CWE ID: CWE-822 (Untrusted Pointer Dereference)
  • CVSS 3.1 Base Score: 7.8 (HIGH)
  • Attack Vector: Local (AV:L)
  • Privileges Required: Low (PR:L)
  • Impact: Total on Confidentiality, Integrity, and Availability (C:H/I:H/A:H)
  • Full Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

📊 Technical Details Table (NVD)


💻 Affected Systems

The vulnerability affects the following Windows versions:

  • Windows 11 24H2 (x64 and arm64) - up to build 10.0.26100.7781
  • Windows 11 25H2 (x64 and arm64) - up to build 10.0.26200.7781
  • Windows 11 26H1 (x64 and arm64) - up to build 10.0.28000.1575
  • Windows Server 2022 (23H2) - up to build 10.0.25398.2149
  • Windows Server 2025 - up to build 10.0.26100.32313

🔹 Note: Versions later than the mentioned builds are not vulnerable (patched in February 2026).


⚠️ Exploitation Impact

An attacker who successfully exploits this vulnerability could obtain SYSTEM privileges, allowing:

  • Full system control
  • Access to confidential data
  • Modification of system integrity
  • Disruption of availability

🛠️ Mitigation and Patches

It is recommended to apply the security updates provided by Microsoft:

🔧 Required Action

✅ Apply security patches immediately from:

  • Microsoft Security Update Guide (CVE-2026-21250)

📋 Exploitation Status

  • Public Disclosure: No
  • Exploited in Attacks: No
  • Exploit Code Maturity: Not tested
  • Remediation Level: Official patch available
  • Report Confidence: Confirmed

⚠️ FAQ

Q: What privileges can an attacker obtain by exploiting this vulnerability? 🔹 A: SYSTEM privileges (NT AUTHORITY\SYSTEM), allowing full system control.


🔗 Official References

  • Microsoft Security Response Center (MSRC)
  • National Vulnerability Database (NVD)
  • CVE-2026-21250 on CVE.org

⚖️ Disclaimer

This content is for exclusively educational and cybersecurity research purposes. The information is provided "as is" without warranty of any kind. Users are responsible for complying with all applicable laws and regulations.


Last updated: Feb 10, 2026
Version: 1.0

Download Tool
MetricValueDescription
CWE IDCWE-822Untrusted Pointer Dereference
CVSS 3.1 Base Score7.8 (HIGH)Severity score
CVSS VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HLocal, low complexity, no interaction
CVE PublishedFebruary 10, 2026Official release date
Report confidenceConfirmedValidated by Microsoft and NVD
Operating SystemArchitectureMaximum Vulnerable Build
Windows 11 24H2x64 / ARM6410.0.26100.7781
Windows 11 25H2x64 / ARM6410.0.26200.7781
Windows Server 2022 (23H2)x6410.0.25398.2149
Windows Server 2025x6410.0.26100.32313
Operating SystemKBBuildDate
Windows 11 24H2 (x64)5077181 / 507721210.0.26100.7840 / 7781Feb 10, 2026
Windows 11 24H2 (ARM64)5077181 / 507721210.0.26100.7840 / 7781Feb 10, 2026
Windows 11 25H2 (x64)5077181 / 507721210.0.26200.7840 / 7781Feb 10, 2026
Windows 11 25H2 (ARM64)5077181 / 507721210.0.26200.7840 / 7781Feb 10, 2026
Windows Server 2022 23H2507589710.0.25398.2149Feb 10, 2026
Windows Server 20255075899 / 507594210.0.26100.32370 / 32313Feb 10, 2026