CVE-2026-21232
vulnerability analysis and mitigation

Overview

CVE-2026-21232 is a local privilege escalation vulnerability caused by an untrusted pointer dereference in the Windows HTTP.sys kernel driver. It allows an authorized (low-privileged) local attacker to elevate privileges to SYSTEM level. Affected products include Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 23H2 and Windows Server 2025. The vulnerability was disclosed and patched on February 10, 2026, as part of Microsoft's Patch Tuesday release. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).

Technical details

The root cause is classified as CWE-822 (Untrusted Pointer Dereference), occurring within the Windows HTTP.sys kernel driver. An attacker who already has low-privileged local access can supply a crafted pointer value that the driver dereferences without adequate validation, leading to kernel-level code execution. The attack vector is local, requires low privileges, no user interaction, and has low attack complexity, making it straightforward to exploit once local access is obtained. No public technical write-ups or proof-of-concept code have been identified at this time (Microsoft MSRC, Qualys Blog).

Impact

Successful exploitation grants a low-privileged attacker complete SYSTEM-level control over the affected machine, resulting in high impact to confidentiality, integrity, and availability. An attacker could read sensitive data, modify system files, install malware, disable security controls, or use the compromised host as a pivot point for lateral movement within a network. Affected systems span a broad range of modern Windows deployments including Windows 11 (23H2 through 26H1) and Windows Server 2022/2025 (Microsoft MSRC, Feedly).

Mitigation and workarounds

Microsoft released patches on February 10, 2026, as part of the February 2026 Patch Tuesday update. Organizations should update to the following minimum versions: Windows 11 23H2 → 10.0.22631.6649, Windows 11 24H2 → 10.0.26100.7781, Windows 11 25H2 → 10.0.26200.7781, Windows Server 2022 23H2 → 10.0.25398.2149, and Windows Server 2025 → 10.0.26100.32313. As a compensating control, restrict local interactive and remote desktop access to systems, enforce the principle of least privilege for user accounts, and prioritize patching for internet-facing and production server environments (Microsoft MSRC, Qualys Blog).

Community reactions

The February 2026 Patch Tuesday was broadly covered by security media, with BleepingComputer noting the release fixed 58 flaws including 6 zero-days, though CVE-2026-21232 was not among the zero-days being actively exploited (BleepingComputer). Qualys and Rapid7 both included the vulnerability in their Patch Tuesday review blogs, recommending prompt patching given the SYSTEM-level privilege escalation potential (Qualys Blog, Rapid7 Blog). Sophos also covered the update in their February Patch Tuesday analysis (Sophos Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management