Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Microsoft
CVE-2026-21250 CVSS 7.8
2026-02-10 08:00 UTC · 2026-02-10 05:00 -03
Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
https://security-tracker.debian.org/tracker/DSA-6129-1