CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys
Brief
In this excerpt of a TrendAI Research Services vulnerability report, Yazhi Wang and Jonathan Lein of the TrendAI Research team detail a recently patched remote code execution bug in the Windows HTTP protocol stack. Successful exploitation of this vulnerability can result in a denial-of-service condition, or, in the worst case, code execution with kernel privileges.
The following is a portion of their write-up covering CVE-2026-47291, with a few minimal modifications. A remote code execution vulnerability exists in the HTTP Protocol Stack for Microsoft Internet Information Services implemented in HTTP. sys. The vulnerability is due to invalid validating incoming HTTP requests.
A remote, unauthenticated attacker can exploit this vulnerability by sending crafted HTTP packets to the target system.
