CVE-2026-20929
published 2026-01-13CVE-2026-20929: Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
PriorityP262high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EXPLOIT
EPSS
2.91%
86.5th percentile
Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1607 | < 10.0.14393.8783 | 10.0.14393.8783 |
| microsoft | windows_10_1809 | < 10.0.17763.8276 | 10.0.17763.8276 |
| microsoft | windows_10_21h2 | < 10.0.19044.6809 | 10.0.19044.6809 |
| microsoft | windows_10_22h2 | < 10.0.19045.6809 | 10.0.19045.6809 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.8783 | 10.0.14393.8783 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.8276 | 10.0.17763.8276 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.6809 | 10.0.19044.6809 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.6809 | 10.0.19045.6809 |
| microsoft | windows_11_23h2 | < 10.0.22631.6491 | 10.0.22631.6491 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.6491 | 10.0.22631.6491 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.28117 | 6.1.7601.28117 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.23717 | 6.0.6003.23717 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.25868 | 6.2.9200.25868 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22968 | 6.3.9600.22968 |
| microsoft | windows_server_2016 | < 10.0.14393.8783 | 10.0.14393.8783 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.8783 | 10.0.14393.8783 |
| microsoft | windows_server_2019 | < 10.0.17763.8276 | 10.0.17763.8276 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.8276 | 10.0.17763.8276 |
| microsoft | windows_server_2022 | < 10.0.20348.4648 | 10.0.20348.4648 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.4648 | 10.0.20348.4648 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.2092 | 10.0.25398.2092 |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows HTTP.sys Elevation of Privilege Vulnerability
vendor_msrc·2026-01-13·CVSS 7.5
CVE-2026-20929 [HIGH] CWE-284 Windows HTTP.sys Elevation of Privilege Vulnerability
Windows HTTP.sys Elevation of Privilege Vulnerability
Description: Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
The Attack requires an Service Principal Name (SPN) that is registered to an account that no longer exists or is not in use, to be on the target machine.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows HTTP.sys: Windows HTTP.sys
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;
GHSA
GHSA-cjjj-mhw7-f4xr: Improper access control in Windows HTTP
ghsa_unreviewed·2026-01-13
CVE-2026-20929 [HIGH] CWE-284 GHSA-cjjj-mhw7-f4xr: Improper access control in Windows HTTP
Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
No detection rules found.
Metasploit
ESC8 Relay: SMB to HTTP(S) via Kerberos
metasploit·CVSS 7.5
CVE-2026-20929 [HIGH] ESC8 Relay: SMB to HTTP(S) via Kerberos
ESC8 Relay: SMB to HTTP(S) via Kerberos
This module creates an SMB server and relays the Kerberos AP-REQ passed to it (for example from a coerced host, CVE-2026-20929) to an AD CS Web Enrollment HTTP endpoint to gain an authenticated connection. Once that connection is established, the module makes an authenticated request for a certificate based on a given template. Unlike NTLM, a Kerberos AP-REQ is a complete, self-contained credential bound to the SPN the victim was coerced into requesting, so there is no challenge/response and the relay is a single request. The captured AP-REQ can only be relayed to the service matching that SPN.
Metasploit
DHCPv6 DNS Takeover (mitm6-style IPv6 DNS coercion)
metasploit·CVSS 7.5
CVE-2026-20929 [HIGH] DHCPv6 DNS Takeover (mitm6-style IPv6 DNS coercion)
DHCPv6 DNS Takeover (mitm6-style IPv6 DNS coercion)
This module runs a rogue DHCPv6 server that hands the attacker to IPv6 clients as their DNS server (the classic mitm6 primitive), and a paired DNS server that poisons names under a target domain to point at the attacker while transparently forwarding all other lookups so the victim stays functional. Once a client resolves a target service through the attacker, it can be coerced into authenticating to the attacker. Paired with a Kerberos relay target (for example ESC8 AD CS web enrollment), this is the native coercion half of the Kerberos relay via DNS technique (CVE-2026-20929), removing the dependency on external tooling such as mitm6. IPv6 is preferred by Windows over IPv4, so becoming the client's IPv6 DNS server is enough to intercep
Metasploit
IPv6 Router Advertisement DNS Takeover (RDNSS IPv6 DNS coercion)
metasploit·CVSS 7.5
CVE-2026-20929 [HIGH] IPv6 Router Advertisement DNS Takeover (RDNSS IPv6 DNS coercion)
IPv6 Router Advertisement DNS Takeover (RDNSS IPv6 DNS coercion)
This module runs a rogue IPv6 router that advertises the attacker as the recursive DNS server (RDNSS, RFC 8106) inside Router Advertisements, and a paired DNS server that poisons names under a target domain to point at the attacker while transparently forwarding all other lookups so the victim stays functional. It is the Router Advertisement equivalent of the mitm6 DHCPv6 DNS takeover: instead of answering DHCPv6 Solicits, it multicasts RAs carrying an RDNSS option, which modern Windows (and other RFC 8106 clients) adopt as their IPv6 resolver. It also listens for Router Solicitations and replies with a unicast RA immediately, so a client is coerced the moment it boots or refreshes rather than waiting for the next unsolicite
Rapid7
Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?
blogs_rapid7·2026-09-25·CVSS 10.0
CVE-2026-85706 [CRITICAL] Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?
This wrap-up comes from the beautiful country of Belgium, where the Metasploit team is team-building and team-eating while we cheer on our very own teammates giving talks - shout-out to @jburgess-r7 who gave a wonderful talk about some of his 0day research.
Team building is a wonderful corporate ritual in which security researchers — people whose job is to break stuff and find ways into places they shouldn't be — are released into hotels full of questionable tech, and then everyone acts surprised by what happens next. So far, the only leak has been the Manneken Pis.
Anyway, while we were busy learning that a country with three official languages still has zero words for "one waffle is enough," the internet continued to be on fire.
We’re gonna jump right into the deep end. GitLab. Unauth
Rapid7
Metasploit Wrap Up: This One Goes to Sixteen!
blogs_rapid7·2026-09-11·CVSS 8.4
CVE-2025-66516 [HIGH] Metasploit Wrap Up: This One Goes to Sixteen!
## This One Goes to Sixteen!
Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers!
## New module content (16)
## Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read
Authors: Bourbon Offensive Security Services and Jean-Marie Bourbon
Type: Auxiliary
Pull request: #21739 contributed by kmkz
Path: scanner/http/elasticsearch_tika_xfa_xxe
CVE reference: CVE-2025-66516
Description: Adds an auxiliary scanner module for CVE-2025-54988/CVE-2025-66516. The module validates an XML External Entity (XXE) vulnerability in Apache Tika's XFA parser exposed thro
Hackernews
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
blogs_hackernews·2026-04-13·CVSS 8.6
[HIGH] ⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
Monday is back, and the weekend’s backlog of chaos is officially hitting the fan. We are tracking a critical zero-day that has been quietly living in your PDFs for months, plus some aggressive state-sponsored meddling in infrastructure that is finally coming to light. It is one of those mornings where the gap between a quiet shift and a full-blown incident response is basically non-existent.
The variety this week is particularly nasty. We have AI models being turned into autonomous exploit engines, North Korean groups playing the long game
Bleepingcomputer
Microsoft January 2026 Patch Tuesday fixes 3 zero-days, 114 flaws
blogs_bleepingcomputer·2026-01-13·CVSS 5.5
[MEDIUM] Microsoft January 2026 Patch Tuesday fixes 3 zero-days, 114 flaws
## Microsoft January 2026 Patch Tuesday fixes 3 zero-days, 114 flaws
## Lawrence Abrams
57 Elevation of Privilege vulnerabilities
3 Security Feature Bypass vulnerabilities
22 Remote Code Execution vulnerabilities
22 Information Disclosure vulnerabilities
2 Denial of Service vulnerabilities
5 Spoofing vulnerabilities
When BleepingComputer reports on Patch Tuesday security updates, we only count those released by Microsoft today. Therefore, the number of flaws does not include Microsoft Edge (1 flaw) and Mariner vulnerabilities fixed earlier this month.
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5074109 & KB5073455 cumulative updates and Windows 10 KB5073724 extended security update .
## 3 zero-days, one ex
Wiz
CVE-2026-20929 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-20929 [HIGH] CVE-2026-20929 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20929 :
vulnerability analysis and mitigation
Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
Source : NVD
## 7.5
Score
Published January 13, 2026
Severity HIGH
CNA Score 7.5
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13.6
Exploitation Probability (EPSS) N/A
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
Free Vulnerability Assessment
## Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your de
Crowdstrike
What is Cloud Native, Anyway?
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] What is Cloud Native, Anyway?
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Crowdstrike
CrowdStrike@ Black Hat 2020
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] CrowdStrike@ Black Hat 2020
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2026-01-13
Published