CVE-2026-50420
Analyzed Analyzed - Analysis Complete

Out-of-Bounds Read in Windows HTTP.sys

Vulnerability report for CVE-2026-50420, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50420 is an out-of-bounds read vulnerability in the Windows HTTP.sys component. This flaw allows an unauthorized attacker to access and disclose sensitive information locally on the affected system.

An out-of-bounds read occurs when a program reads data beyond the intended boundary of a buffer or memory region. In this case, the vulnerability in HTTP.sys could enable an attacker to read memory contents that they should not have access to, potentially exposing confidential data.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the presence of CVE-2026-50420 on a network or system. Detection typically involves checking the installed version of HTTP.sys or applying security updates released by Microsoft.

To verify if your system is vulnerable, you can check the version of HTTP.sys. However, the exact version or patch level required to mitigate this vulnerability is not specified in the provided context. Refer to Microsoft's official guidance for version details and detection steps.

Impact Analysis

This vulnerability can impact you in the following ways:

  • Information disclosure: An attacker could exploit this flaw to access sensitive data stored in memory, such as credentials, personal information, or other confidential details.
  • Local exploitation: Since the attack vector is local (AV:L), the attacker must have access to the system to exploit the vulnerability. This could occur if an attacker already has a foothold on the machine or if the system is shared among multiple users.
  • No integrity or availability impact: The vulnerability does not allow the attacker to modify data or disrupt system operations, as it only affects confidentiality.
Compliance Impact

This vulnerability could affect compliance with common standards and regulations in the following ways:

  • GDPR: If the disclosed information includes personal data of EU citizens, this vulnerability could lead to a breach of GDPR requirements. GDPR mandates that organizations protect personal data from unauthorized access, and failure to do so could result in significant fines or legal consequences.
  • HIPAA: For organizations handling protected health information (PHI) in the U.S., this vulnerability could result in a HIPAA violation if the disclosed information includes PHI. HIPAA requires safeguards to ensure the confidentiality of health information, and a breach could lead to penalties.
  • Other regulations: Depending on the industry and type of data involved, this vulnerability could also impact compliance with other standards such as PCI DSS (for payment card data) or sector-specific regulations.

Organizations should assess whether the vulnerability exposes regulated data and take appropriate measures to mitigate the risk, such as applying patches or implementing compensating controls.

Mitigation Strategies

Apply the security update provided by Microsoft to address CVE-2026-50420. The update will patch the out-of-bounds read vulnerability in HTTP.sys.

  • Visit the Microsoft Security Response Center (MSRC) update guide for CVE-2026-50420 to download and install the latest patch.
  • Ensure all Windows systems running the affected HTTP.sys component are updated to the latest secure version.

If immediate patching is not possible, consider implementing network-level protections or monitoring for unusual activity, though these are not substitutes for applying the official patch.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50420. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart