Windows HTTP.sys RCE – CVE-2026-47291

TL;DR: CVE-2026-47291 is a critical (CVSS 9.8) integer-overflow flaw in HTTP.sys, the kernel-mode driver that handles HTTP for IIS, WinRM and dozens of other Windows services. An unauthenticated attacker can send a single crafted HTTP request over the network and run code in the Windows kernel — no login, no clicks. Microsoft patched it in the June 2026 update and rates it “Exploitation More Likely”. Patch now.

Key takeaways

  • Pre-authentication, network-reachable remote code execution in the Windows kernel HTTP stack — the worst class of Windows bug there is.
  • Affects every supported version of Windows client and Windows Server that exposes HTTP/HTTPS, which in practice is almost all of them.
  • CVSS 9.8. Microsoft flags it “Exploitation More Likely”; no public proof-of-concept or in-the-wild exploitation is confirmed as of 29 June 2026.
  • A patch shipped on 9 June 2026 (Patch Tuesday). There is no clean configuration-only fix — apply the cumulative update.
  • HTTP.sys has a track record (CVE-2021-31166, CVE-2022-21907), so treat this as a “patch before a working exploit lands” situation.

Critical Windows HTTP.sys RCE CVE-2026-47291
CVSS Score9.8  (CVSS v3.1, Microsoft)
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability TypeInteger overflow leading to heap-based buffer overflow / RCE  (CWE-190, CWE-122)
Affected ProductsMicrosoft Windows (client and server) — Windows 10, Windows 11, and Windows Server 2016, 2019, 2022 and 2025, on any build prior to the June 2026 cumulative update
Attack VectorNetwork — unauthenticated, no user interaction
Actively ExploitedNo confirmed in-the-wild exploitation as of 29 June 2026  (not in CISA KEV; Microsoft: “Exploitation More Likely”; no public PoC)
Patch AvailableYes — fixed in the June 2026 Patch Tuesday cumulative update
Disclosure Date9 June 2026 (Microsoft Patch Tuesday)

What is CVE-2026-47291?

CVE-2026-47291 is a critical remote code execution vulnerability in HTTP.sys, the kernel-mode HTTP protocol stack built into Windows. Microsoft disclosed it on 9 June 2026 as part of a record-breaking Patch Tuesday and assigned it a CVSS v3.1 base score of 9.8. The flaw is an integer overflow (CWE-190) in the way HTTP.sys parses incoming requests, which corrupts kernel heap memory (CWE-122) and can be steered into code execution.

HTTP.sys is not an optional add-on. It is the driver that sits underneath Internet Information Services (IIS), Windows Remote Management (WinRM), WSDAPI, and a long list of products and services that listen on HTTP or HTTPS — from print services to management consoles to third-party applications that host their own web endpoints. Because the driver runs in kernel mode, a successful exploit gives an attacker the highest possible privileges on the machine, with no privilege boundary above them. That combination — unauthenticated, network-reachable, kernel-level — is why this is a marquee entry in an unusually large June update.

How the Windows HTTP.sys exploit works

In plain terms: an attacker sends a Windows machine a specially malformed web request, and the part of Windows that reads that request miscounts how much memory it needs. That miscount lets the attacker’s data spill into memory it should never touch, and from there an attacker can take control of the system.

In more detail, the root cause is an arithmetic error. When HTTP.sys processes an incoming request, it performs size calculations on attacker-influenced fields — for example, header lengths or chunked-encoding values. An integer overflow occurs when one of these calculations wraps around past the maximum value the variable can hold, producing a result that is far smaller than the real size of the data. The driver then allocates a buffer based on the wrong, undersized figure and copies the larger payload into it, overflowing the adjacent kernel heap. With careful shaping of the heap and follow-up requests, that memory corruption can be converted into execution of attacker-chosen code in kernel context — i.e. as the operating system itself.

The pre-conditions are minimal, which is what makes it dangerous. The attacker needs network reachability to a port served by HTTP.sys (typically 80/443, but any HTTP.sys-backed listener counts) and no credentials, no existing foothold and no interaction from a user or administrator. The request reaches the kernel parser before any application-layer authentication runs, so an unauthenticated web server, a management interface, or any exposed Windows service riding on HTTP.sys is in scope.

The illustrative, non-operational sketch below shows only the shape of the trigger — an oversized/malformed length field — not a working exploit. No offsets, gadgets or payload are provided, and none will be.

# ILLUSTRATIVE ONLY — not a working exploit.
# A request whose declared length field is crafted to wrap a size
# calculation inside HTTP.sys (conceptual, non-functional):
POST /any-httpsys-endpoint HTTP/1.1
Host: target
Content-Length: <value chosen to overflow an internal size calc>
Transfer-Encoding: chunked
<malformed chunk-size / header construction that triggers the
miscalculation — details deliberately omitted>

This mirrors the pattern of earlier HTTP.sys bugs such as CVE-2021-31166 and CVE-2022-21907, where malformed request parsing in the same driver led to memory corruption. The lesson from those is that HTTP.sys flaws move from advisory to public proof-of-concept quickly once researchers reverse the patch.

Is CVE-2026-47291 actively exploited?

As of 29 June 2026 there are no confirmed reports of in-the-wild exploitation, no public proof-of-concept exploit, and the CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalogue. Microsoft has, however, placed it on its “Exploitation More Likely” track in the Security Update Guide — its assessment that a working exploit is realistically achievable and worth attackers’ time.

That status should not be read as “low risk”. A pre-authentication kernel RCE on a near-universal Windows attack surface is exactly the kind of bug that exploit brokers and red-team researchers prioritise, and the Zero Day Initiative’s review of the June updates singled the HTTP.sys-class flaws out as ones every research team would be reversing immediately. Given the history of the driver, the prudent assumption is that the window between disclosure and a usable exploit is short. Treat this as urgent now, not after the first incident report.

How to fix CVE-2026-47291: remediation & mitigation

Patch: Install the June 2026 Patch Tuesday cumulative update (released 9 June 2026) on every affected Windows client and server via Windows Update, WSUS, or the Microsoft Update Catalogue. Confirm the exact KB article and build number for each OS in Microsoft’s Security Update Guide entry for CVE-2026-47291 before deploying, and verify the installed build post-patch. There is no supported configuration change that removes the flaw itself — the code fix is the fix.

Prioritise:

  • Internet-facing Windows web servers and any host exposing IIS, WinRM, or other HTTP.sys-backed listeners to untrusted networks.
  • Management and appliance-style Windows systems whose web consoles are reachable across internal network segments.
  • Domain controllers and other high-value servers, even where the HTTP surface is “internal only” — lateral movement makes internal exposure meaningful.

If you cannot patch immediately:

  • Restrict network access to HTTP.sys-backed ports (80/443 and any custom listeners) using host and perimeter firewalls, so only known clients can reach them. This reduces exposure but does not remediate the vulnerability.
  • Take genuinely non-essential HTTP/HTTPS listeners offline until the update is applied.
  • Front exposed services with a reverse proxy or WAF that strictly validates and normalises request framing (header lengths, Content-Length, chunked encoding). This may blunt naive trigger attempts but cannot be relied upon as a substitute for the patch.

After patching: Review logs on previously exposed hosts for signs of pre-patch probing — unexplained HTTP.sys / http service crashes, Schannel or HttpEvent errors, or worker-process restarts around malformed requests can indicate attempted exploitation. On any system you suspect was reachable and unpatched, treat a kernel-level compromise as plausible: hunt for new services, scheduled tasks and accounts, and rotate credentials held on the host.

Detection / IOCs: No vendor or community indicators of compromise are published for CVE-2026-47291 as of 29 June 2026. In the absence of specific IOCs, monitor for anomalous HTTP.sys driver faults and unexpected kernel crashes (bugchecks) on HTTP-serving hosts, and watch vendor and CISA channels for KEV addition or PoC release, which would sharply raise urgency.

Frequently asked questions

How serious is CVE-2026-47291?

Very. A CVSS score of 9.8 reflects an unauthenticated, network-exploitable bug that compromises confidentiality, integrity and availability. Because the vulnerable code runs in the Windows kernel, success means SYSTEM-level control of the machine, not just a single application.

Do I need to do anything if I do not run IIS?

Probably yes. HTTP.sys underpins far more than IIS — WinRM, various management interfaces, and many third-party applications that self-host web endpoints all use it. If any process on the machine listens on HTTP/HTTPS, the driver is in play. The safe approach is to patch all supported Windows systems.

Is there a working exploit in the wild?

Not as of 29 June 2026. There is no public proof-of-concept and the flaw is not in CISA KEV. Microsoft rates exploitation “more likely”, and HTTP.sys bugs have historically been weaponised quickly, so the absence of an exploit today is not a reason to defer patching.

Can a firewall fix it instead of patching?

No. Restricting access to HTTP.sys ports reduces who can reach the vulnerable code, which is worthwhile as an interim measure, but it does not remove the flaw. Only the June 2026 update remediates CVE-2026-47291.

Sources & further reading


ZeroDayHub tracks critical vulnerabilities as they break. Subscribe for updates.

One response to “Windows HTTP.sys Unauthenticated RCE – CVE-2026-47291”

  1. […] And for the initial-access half of the chain these EoP flaws depend on, our coverage of the Windows HTTP.sys unauthenticated RCE (CVE-2026-47291) shows how attackers get their first foot in the door. Put a remote entry point and a reliable […]

Leave a Reply

Trending

Discover more from Zerodayhub

Subscribe now to keep reading and get access to the full archive.

Continue reading