Executive brief
A vulnerability in how Microsoft Windows handles HTTP/2 network traffic could allow an attacker to crash or slow down a system remotely. This type of attack, known as a Denial of Service, can disrupt business operations by making web services or connected servers unavailable to legitimate users. No special access or user interaction is required for an attacker to trigger this issue.
Technical details
A Denial of Service (DoS) vulnerability exists in the Microsoft Windows HTTP/2 stack due to improper resource management (CWE-770). The flaw stems from the allocation of resources without sufficient limits or throttling when processing HTTP/2 streams. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP/2 requests over the network, leading to resource exhaustion and a system hang or crash. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server 2016. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 Versions 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 All versions including Server Core
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory: Microsoft released security updates and advisory.