CVE-2026-47291, Microsoft June Patch Tuesday: HTTP.sys pre-auth RCE (CVSS 9.8) headlines the largest-ever release (198 CVEs)
Defender actions
- Deploy the June Patch Tuesday HTTP.sys fix (CVE-2026-47291) on any IIS/WinRM host; as an interim check, confirm
MaxRequestBytesis at the 16384-byte default (raised values are the exposed configuration). Apply the Chrome 149.0.7827.103 update fleet-wide for the in-the-wild V8 zero-day CVE-2026-11645 (CISA KEV). - Confirm the June 2026 Windows cumulative update is applied on every internet-facing IIS/HTTPS host and any service built on the HTTP Server API; ZDI notes the patch is the only reliable remediation.
- As an interim measure on unpatched hosts, keep the HTTP.sys
MaxRequestBytesregistry value (HKLM\\SYSTEM\\CurrentControlSet\\Services\\HTTP\\Parameters) at or below 65,535 bytes; a request must be able to carry ~262,144 bytes to trigger the overflow, so this configuration blocks it. - Where TLS inspection exists, alert on any single HTTP/1.x request carrying more than ~1,000 header field lines; without decryption, flag HTTPS connections that send more than ~1,000 tiny TLS application-data records over roughly 11 minutes.
Analysis
Microsoft's June 2026 Patch Tuesday addressed 198 CVEs (32 Critical), the largest in program history (Rapid7, 2026-06-09). The headline is CVE-2026-47291 in HTTP.sys (CWE-190 integer overflow into a CWE-122 heap write): an unauthenticated attacker sends a crafted request to any Windows service built on the HTTP Protocol Stack (IIS, WinRM, WMI-over-HTTP) to achieve RCE, rated "Exploitation More Likely" (Microsoft MSRC, 2026-06-09). Microsoft notes systems at the default MaxRequestBytes of 16384 bytes are not impacted; only deployments that raised it above ~65 KB are exposed, so resetting that registry value is a stopgap. Three publicly-disclosed (not-yet-exploited) zero-days also shipped: CVE-2026-49160 (HTTP.sys HTTP/2 compression-bomb DoS, the IIS analogue of the earlier nginx/Apache CVE-2026-49975, now mitigated with MaxHeadersCount), CVE-2026-50507 (BitLocker physical-access bypass), and CVE-2026-45586 (CTFMON EoP); the release also includes the DHCP Client RCE CVE-2026-44815 (CVSS 9.8, "Less Likely") and VSCode EoP CVE-2026-47281 (CVSS 9.6) (Tenable, 2026-06-09; SANS ISC, 2026-06-09). Prioritise the HTTP.sys patch on any Windows host exposing IIS/WinRM.
Cited evidence
The vulnerability is only reachable through HTTP/1.x header parsing over TLS connections. HTTP/2 and HTTP/3 use different parser paths that do not interact with the buffer reference array.
If the number of header field lines in a single request exceeds 1,000, the traffic should be considered suspicious; an attack exploiting this vulnerability is likely underway.
Updates1
CVE-2026-47291 shipped in the June 2026 Patch Tuesday as a headline pre-auth RCE in HTTP.sys, the kernel-mode HTTP driver that terminates HTTP/1.x and TLS for IIS and every service built on the HTTP Server API. The delta is a full exploitation write-up from Zero Day Initiative's TrendAI Research team, published a month after the patch, that documents the precise defect and trigger and materially lowers the weaponisation bar (Zero Day Initiative, 2026-07-10).
The bug is a 16-bit integer overflow in the buffer-reference array that HTTP.sys grows while parsing HTTP/1.x headers: the capacity counter is incremented by five on each growth without a bounds check, and after 13,107 growths it reaches 0xFFFB, so the next increment wraps to 0x0000; the subsequent reference addition then allocates a 40-byte buffer but memmoves roughly 524,256 bytes into it, a ~500 KB kernel-pool heap overflow. Because SChannel delivers each TLS record to the parser as its own buffer, an attacker who places exactly one header line per TLS application-data record establishes a 1:1 record-to-reference correspondence and drives the counter to overflow with a single ~262 KB request. Successful exploitation crashes the box (kernel memory-access exception) and, under favourable pool layout, can execute code in kernel context. Critically, the path is reachable only via HTTP/1.x-over-TLS; HTTP/2 and HTTP/3 use a different parser and are unaffected (Zero Day Initiative, 2026-07-10).
The write-up also corrects the exposure picture the original advisory left fuzzy: the default MaxRequestBytes of 16,384 bytes caps a request at roughly 4,000 header lines (far short of the ~65,536 references needed) so only hosts that raised MaxRequestBytes to at least 262,144 bytes can be driven to the overflow. Microsoft rates the CVE "Exploitation More Likely"; no in-the-wild exploitation is reported as of ZDI's publication (Microsoft MSRC, 2026-06-09).
Sources6
Revision history
- Published 2026-06-10-c84347b2
- Update 2026-07-11T0409Z-intel
Zero Day Initiative published a full technical write-up (2026-07-10) of CVE-2026-47291, the HTTP.sys pre-auth kernel RCE patched in Microsoft's June 2026 cycle, documenting the exact integer-overflow arithmetic and the TLS-record-fragmentation trigger. Not yet exploited in the wild, but the mechanics (and a concrete network-detection heuristic) are now public, so anyone running an internet-facing IIS/HTTPS listener that missed the June patch should treat it as newly weaponisable.
Changed: actions affected_products cves evidence sectors sources tags techniques body
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.