Junglewise Threat Intelligence

CVE-2021-31166: Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability

CVE-2021-31166 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-04-06

Vendors: Microsoft.

Executive brief

A use-after-free vulnerability in the Microsoft HTTP Protocol Stack (http.sys) allows unauthenticated remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted packets. The vulnerability is highly critical due to its wormable potential and lack of required user interaction.

Affected products

  • Microsoft Windows 10 Version 2004 up to (excluding) 10.0.19041.982
  • Microsoft Windows 10 Version 20H2 up to (excluding) 10.0.19042.982
  • Microsoft Windows Server version 2004 up to (excluding) 10.0.19041.982
  • Microsoft Windows Server version 20H2 up to (excluding) 10.0.19042.982

Timeline

  • 2021-05-11: disclosed: NVD Published Date
  • 2021-05-11: patched: MSRC advisory and patch released
  • 2022-04-06: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-06: exploited: Confirmed exploited in the wild per CISA KEV entry