Security Advisory on Integer Overflow Vulnerability in Windows HTTP.sys (CVE-2026-62735)
# Security risk notice for Windows HTTP.sys integer overflow vulnerability (CVE-2026-62735) ## Overview of the vulnerability | Item | Description | |------|------------| | Vulnerability name | Windows HTTP Sys integer overflow vulnerability | | Vulnerability ID | CVE-2026-62735 | | Vulnerability ID (QVD) | QVD-2026-51050 | | Publication date | 2026-08-11 | | Impact scale | Million-level | | CISSP rating | High risk | | CVSS score | 7.8 | | Threat type | Privilege escalation | | Exploitability | High | | POC status | Public | | Off-the-shelf exploit status | Not found | ## Description of the harm An attacker can exploit this vulnerability by constructing specially crafted HTTP response header data to trigger integer overflow…