ZeroHour

CVE-2021-31166

KEVmass

Use-After-Free RCE in Microsoft Windows HTTP Protocol Stack (http.sys)

CISA: Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2021-31166 is a use-after-free vulnerability (CWE-416) in the Microsoft HTTP Protocol Stack, the kernel-mode HTTP service (http.sys) used by Windows components including IIS and WinRM. A remote, unauthenticated attacker can trigger the flaw by sending specially crafted network packets to a service that listens through http.sys, and reporting indicates WinRM servers are also impacted. Successful exploitation yields remote code execution in the kernel context, with full compromise potential (high confidentiality, integrity and availability impact), consistent with the wormable classification in vendor-adjacent reporting. Affected platforms are Windows 10 versions 2004 and 20H2 and Windows Server versions 2004 and 20H2, which were the current shipping Windows versions at the May 2021 Patch Tuesday release where the fix appeared. The issue is tracked in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-06) and carries a near-certain EPSS exploitation probability (~99.8%), indicating active exploitation in the wild.

What to do: Apply the May 2021 Patch Tuesday security updates for Windows 10 and Windows Server versions 2004 and 20H2, prioritizing internet-facing systems running IIS, WinRM, or other http.sys-based listeners. As an interim mitigation, restrict inbound access to HTTP and WinRM endpoints at the firewall. Confirm remediation by verifying the OS build includes the May 2021 cumulative update, and check the CISA KEV catalog action (apply updates per vendor instructions).

Affected
Microsoft Windows 10version 2004
Microsoft Windows 10version 20H2
Microsoft Windows Serverversion 2004
Microsoft Windows Serverversion 20H2
Microsoft HTTP Protocol Stack (http.sys)as shipped in Windows 10/Windows Server versions 2004 and 20H2
Estimated exposure
masswell over 1,000,000 vulnerable systems (tens of millions of Windows 10 2004/20H2 installs, with likely hundreds of thousands of internet-exposed servers via… — Windows 10 versions 2004 and 20H2 were the then-current shipping versions in May 2021 within an install base exceeding one billion devices, and public internet scans of Windows servers routinely show large numbers exposing http.sys-based…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

HTTP Protocol Stack Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft HTTP Protocol Stack
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 2004, windows 10 20h2, windows server 2004, windows server 20h2
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news