CVE-2026-62735 is a heap-based buffer overflow in Windows HTTP.sys. An authorized attacker with local access can exploit the flaw to elevate privileges to SYSTEM.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file C++ repository is a standalone, non-framework exploit repository for CVE-2026-62735, an alleged Microsoft HTTP.sys local elevation-of-privilege vulnerability. It contains two independently compilable variants: `crash/poc.cpp` with `crash/head.hpp` is a vulnerability-validation trigger intended to crash the kernel, while `poc/poc.cpp` with `poc/head.hpp` implements the complete privilege-escalation chain. Both variants initialize the Windows HTTP Server API, register `http://127.0.0.1:8088/poc/`, make a loopback WinHTTP GET request, receive it through an HTTP request queue, and call `DeviceIoControl` with IOCTL `0x12403F` to make HTTP.sys process a crafted response. The trigger constructs numerous multiple-known HTTP response headers whose accumulated byte count wraps a 32-bit calculation. HTTP.sys consequently allocates an undersized nonpaged-pool buffer and subsequently copies substantially more header data, yielding a controlled pool overflow. The crash version sets the layout to cause a reproducible HTTP.sys `memcpy` fault/0x50 bugcheck. The full PoC places a forged named-pipe `DATA_QUEUE_ENTRY` in the overflow data, performs named-pipe data-queue heap spraying and grooming, then abuses the corrupted queue to leak and overwrite kernel memory. It uses hard-coded EPROCESS/KTHREAD offsets to find the current process and PID 4 System process, copies the System token pointer into the current EPROCESS token field, cleans up helper I/O, and launches `cmd.exe`. README documentation claims public reproduction against Windows 11 25H2 build 26200.8875 and identifies build 26200.9168 as fixed. No external command-and-control, remote payload download, or non-loopback network destination is present.
This is a standalone Windows C++ exploit repository for CVE-2026-62735, not a Metasploit/Nuclei-style framework module. It contains two implementations: `crash/` is a compact reproducer intended to demonstrate the HTTP.sys integer-overflow-driven heap overflow and resulting system crash; `poc/` is the full local privilege-escalation implementation. Both register a local HTTP Server API endpoint, send a loopback GET request, receive that request through an HTTP request queue, and directly submit a crafted response through IOCTL 0x12403F. The crafted response uses many HTTP_MULTIPLE_KNOWN_HEADERS plus a trailer data chunk to cause arithmetic wraparound in HTTP.sys header-size accounting. HTTP.sys allocates an undersized nonpaged-pool buffer and subsequently copies substantially more header/trailer data, corrupting adjacent pool memory. The full PoC's `poc/head.hpp` defines build-specific Windows kernel structures, EPROCESS offsets, named-pipe data-queue/IRP structures, and native API declarations. `poc/poc.cpp` shapes the overflow into a forged DATA_QUEUE_ENTRY, sprays and manipulates named pipes, derives kernel addresses, and obtains kernel read/write operations. It walks process structures to identify PID 4, replaces the current process token with the SYSTEM token, performs cleanup of pending pipe operations, and starts `cmd.exe`. The only network destination is loopback `127.0.0.1:8088/poc/`; this is fundamentally a local attack because the attacker runs the vulnerable HTTP API server and interacts with the local http.sys driver rather than attacking a remote service.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.