---
schema: 1
kind: vulnerability
title: >
  CVE-2026-47291 — Microsoft June Patch Tuesday: HTTP.sys pre-auth RCE (CVSS 9.8) headlines the
  largest-ever release (198 CVEs)
headline: >
  CVE-2026-47291 — Microsoft June Patch Tuesday: HTTP.sys pre-auth RCE (CVSS 9.8) headlines the
  largest-ever release (198 CVEs)
summary: >
  June Patch Tuesday is the largest ever (198 CVEs) — headline is an HTTP.sys pre-auth RCE
  (CVE-2026-47291, CVSS 9.8); separately Chrome patched an in-the-wild V8 zero-day
  (CVE-2026-11645, now CISA KEV). (Rapid7, 2026-06-09; Chrome, 2026-06-08).
discovered_at: "2026-06-10T05:00:05Z"
updated_at: "2026-07-11T04:30:43Z"
event_date: 2026-06-09
run_id: 2026-06-10-c84347b2
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - pre-auth
  - rce
  - poc-public
regions:
  - global
sectors:
  - public-sector
  - energy
  - finance
  - healthcare
  - telco
  - transport
entities: []
techniques:
  - T1190
  - T1499
affected_products:
  - Microsoft Windows Server (HTTP.sys/IIS)
  - Microsoft Windows 10
  - Microsoft Windows 11
cves:
  - id: CVE-2026-47291
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - poc-public
      - patch-available
    affected: >
      Windows 10 (1607/1809/21H2/22H2), Windows 11 (23H2/24H2/25H2/26H1) pre-June-2026 cumulative
      update
    fixed: June 2026 cumulative update
  - id: CVE-2026-44815
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-47281
    cvss: "9.6"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-49160
    cvss: "7.5"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
  - id: CVE-2026-50507
    cvss: "6.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-47291"
    publisher: "Microsoft MSRC, 2026-06-09"
    role: primary
  - url: "https://www.rapid7.com/blog/post/em-patch-tuesday-june-2026"
    publisher: "Rapid7, 2026-06-09"
    role: corroborating
  - url: "https://www.tenable.com/blog/microsofts-june-2026-patch-tuesday-addresses-198-cves-cve-2026-49160-cve-2026-50507"
    publisher: "Tenable, 2026-06-09"
    role: corroborating
  - url: "https://isc.sans.edu/diary/rss/33064"
    publisher: "SANS ISC, 2026-06-09"
    role: corroborating
  - url: "https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys"
    publisher: Zero Day Initiative (Trend Micro)
    date: 2026-07-10
    role: primary
  - url: "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291"
    publisher: Microsoft MSRC
    date: 2026-06-09
    role: corroborating
closed_sources: []
evidence:
  - quote: The vulnerability is only reachable through HTTP/1.x header parsing over TLS connections. HTTP/2 and HTTP/3 use different parser paths that do not interact with the buffer reference array.
    publisher: Zero Day Initiative
  - quote: "If the number of header field lines in a single request exceeds 1,000, the traffic should be considered suspicious; an attack exploiting this vulnerability is likely underway."
    publisher: Zero Day Initiative
verification: multi-source
sourcing_note: null
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "**Deploy the June Patch Tuesday HTTP.sys fix (CVE-2026-47291) on any IIS/WinRM host**; as an interim check, confirm `MaxRequestBytes` is at the 16384-byte default (raised values are the exposed configuration). Apply the Chrome 149.0.7827.103 update fleet-wide for the in-the-wild V8 zero-day CVE-2026-11645 (CISA KEV)."
  - "Confirm the June 2026 Windows cumulative update is applied on every internet-facing IIS/HTTPS host and any service built on the HTTP Server API; ZDI notes the patch is the only reliable remediation."
  - "As an interim measure on unpatched hosts, keep the HTTP.sys `MaxRequestBytes` registry value (HKLM\\SYSTEM\\CurrentControlSet\\Services\\HTTP\\Parameters) at or below 65,535 bytes — a request must be able to carry ~262,144 bytes to trigger the overflow, so this configuration blocks it."
  - "Where TLS inspection exists, alert on any single HTTP/1.x request carrying more than ~1,000 header field lines; without decryption, flag HTTPS connections that send more than ~1,000 tiny TLS application-data records over roughly 11 minutes."
updates:
  - at: "2026-07-11T04:30:43Z"
    run_id: 2026-07-11T0409Z-intel
    type: update
    summary: >
      Zero Day Initiative published a full technical write-up (2026-07-10) of CVE-2026-47291, the
      HTTP.sys pre-auth kernel RCE patched in Microsoft's June 2026 cycle, documenting the exact
      integer-overflow arithmetic and the TLS-record-fragmentation trigger. Not yet exploited in the
      wild, but the mechanics — and a concrete network-detection heuristic — are now public, so anyone
      running an internet-facing IIS/HTTPS listener that missed the June patch should treat it as
      newly weaponisable.
    fields:
      - actions
      - affected_products
      - cves
      - evidence
      - sectors
      - sources
      - tags
      - techniques
      - body
    merged_from: 2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics
migrated_from: briefs/2026-06-10.md
---

Microsoft's June 2026 Patch Tuesday addressed 198 CVEs (32 Critical), the largest in program history ([Rapid7, 2026-06-09](https://www.rapid7.com/blog/post/em-patch-tuesday-june-2026)). The headline is CVE-2026-47291 in HTTP.sys (CWE-190 integer overflow into a CWE-122 heap write): an unauthenticated attacker sends a crafted request to any Windows service built on the HTTP Protocol Stack (IIS, WinRM, WMI-over-HTTP) to achieve RCE, rated "Exploitation More Likely" ([Microsoft MSRC, 2026-06-09](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-47291)). Microsoft notes systems at the default `MaxRequestBytes` of 16384 bytes are not impacted — only deployments that raised it above ~65 KB are exposed, so resetting that registry value is a stopgap. Three publicly-disclosed (not-yet-exploited) zero-days also shipped: CVE-2026-49160 (HTTP.sys HTTP/2 compression-bomb DoS, the IIS analogue of the earlier nginx/Apache CVE-2026-49975, now mitigated with `MaxHeadersCount`), CVE-2026-50507 (BitLocker physical-access bypass), and CVE-2026-45586 (CTFMON EoP); the release also includes the DHCP Client RCE CVE-2026-44815 (CVSS 9.8, "Less Likely") and VSCode EoP CVE-2026-47281 (CVSS 9.6) ([Tenable, 2026-06-09](https://www.tenable.com/blog/microsofts-june-2026-patch-tuesday-addresses-198-cves-cve-2026-49160-cve-2026-50507); [SANS ISC, 2026-06-09](https://isc.sans.edu/diary/rss/33064)). Prioritise the HTTP.sys patch on any Windows host exposing IIS/WinRM.

## Update — 2026-07-11T04:30:43Z

CVE-2026-47291 shipped in the June 2026 Patch Tuesday as a headline pre-auth RCE in HTTP.sys, the kernel-mode HTTP driver that terminates HTTP/1.x and TLS for IIS and every service built on the HTTP Server API. The delta is a full exploitation write-up from Zero Day Initiative's TrendAI Research team, published a month after the patch, that documents the precise defect and trigger and materially lowers the weaponisation bar ([Zero Day Initiative, 2026-07-10](https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys)).

The bug is a 16-bit integer overflow in the buffer-reference array that HTTP.sys grows while parsing HTTP/1.x headers: the capacity counter is incremented by five on each growth without a bounds check, and after 13,107 growths it reaches `0xFFFB`, so the next increment wraps to `0x0000`; the subsequent reference addition then allocates a 40-byte buffer but `memmove`s roughly 524,256 bytes into it — a ~500 KB kernel-pool heap overflow. Because SChannel delivers each TLS record to the parser as its own buffer, an attacker who places exactly one header line per TLS application-data record establishes a 1:1 record-to-reference correspondence and drives the counter to overflow with a single ~262 KB request. Successful exploitation crashes the box (kernel memory-access exception) and, under favourable pool layout, can execute code in kernel context. Critically, the path is reachable only via HTTP/1.x-over-TLS — HTTP/2 and HTTP/3 use a different parser and are unaffected ([Zero Day Initiative, 2026-07-10](https://www.zerodayinitiative.com/blog/2026/7/9/cve-2026-47291-remote-code-execution-in-the-windows-httpsys)).

The write-up also corrects the exposure picture the original advisory left fuzzy: the default `MaxRequestBytes` of 16,384 bytes caps a request at roughly 4,000 header lines — far short of the ~65,536 references needed — so only hosts that raised `MaxRequestBytes` to at least 262,144 bytes can be driven to the overflow. Microsoft rates the CVE "Exploitation More Likely"; no in-the-wild exploitation is reported as of ZDI's publication ([Microsoft MSRC, 2026-06-09](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291)). **Defender takeaway:** the patch remains the only reliable fix, but the newly-public mechanics hand defenders a durable network signature — a single HTTP/1.x request bearing more than ~1,000 header lines (visible with TLS inspection), or an HTTPS connection emitting more than ~1,000 tiny TLS records over ~11 minutes (visible without decryption). **Triage:** ordinary browsers and proxies coalesce headers into a few records and never approach that line count, so a single long-lived HTTPS connection feeding one IIS/HTTP.sys request with hundreds-to-thousands of one-line TLS records is the discriminator; a kernel bugcheck on an internet-facing IIS box following such traffic warrants triage against this CVE.
