
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21232 is a local privilege escalation vulnerability caused by an untrusted pointer dereference in the Windows HTTP.sys kernel driver. It allows an authorized (low-privileged) local attacker to elevate privileges to SYSTEM level. Affected products include Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 23H2 and Windows Server 2025. The vulnerability was disclosed and patched on February 10, 2026, as part of Microsoft's Patch Tuesday release. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The root cause is classified as CWE-822 (Untrusted Pointer Dereference), occurring within the Windows HTTP.sys kernel driver. An attacker who already has low-privileged local access can supply a crafted pointer value that the driver dereferences without adequate validation, leading to kernel-level code execution. The attack vector is local, requires low privileges, no user interaction, and has low attack complexity, making it straightforward to exploit once local access is obtained. No public technical write-ups or proof-of-concept code have been identified at this time (Microsoft MSRC, Qualys Blog).
Successful exploitation grants a low-privileged attacker complete SYSTEM-level control over the affected machine, resulting in high impact to confidentiality, integrity, and availability. An attacker could read sensitive data, modify system files, install malware, disable security controls, or use the compromised host as a pivot point for lateral movement within a network. Affected systems span a broad range of modern Windows deployments including Windows 11 (23H2 through 26H1) and Windows Server 2022/2025 (Microsoft MSRC, Feedly).
Microsoft released patches on February 10, 2026, as part of the February 2026 Patch Tuesday update. Organizations should update to the following minimum versions: Windows 11 23H2 → 10.0.22631.6649, Windows 11 24H2 → 10.0.26100.7781, Windows 11 25H2 → 10.0.26200.7781, Windows Server 2022 23H2 → 10.0.25398.2149, and Windows Server 2025 → 10.0.26100.32313. As a compensating control, restrict local interactive and remote desktop access to systems, enforce the principle of least privilege for user accounts, and prioritize patching for internet-facing and production server environments (Microsoft MSRC, Qualys Blog).
The February 2026 Patch Tuesday was broadly covered by security media, with BleepingComputer noting the release fixed 58 flaws including 6 zero-days, though CVE-2026-21232 was not among the zero-days being actively exploited (BleepingComputer). Qualys and Rapid7 both included the vulnerability in their Patch Tuesday review blogs, recommending prompt patching given the SYSTEM-level privilege escalation potential (Qualys Blog, Rapid7 Blog). Sophos also covered the update in their February Patch Tuesday analysis (Sophos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."