CVE-2026-21240 | Microsoft Windows up to Server 2025 HTTP.sys toctou
A vulnerability marked as critical has been reported in Microsoft Windows. This affects an unknown function in the library HTTP.sys. This manipulation causes time-of-check time-of-use.
This vulnerability is registered as CVE-2026-21240. The attack needs to be launched locally. No exploit is available.
It is suggested to install a patch to address this issue.