CVE-2021-31166
KEVmassUse-After-Free RCE in Microsoft Windows HTTP Protocol Stack (http.sys)
CISA: Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability
CVE-2021-31166 is a use-after-free vulnerability (CWE-416) in the Microsoft HTTP Protocol Stack, the kernel-mode HTTP service (http.sys) used by Windows components including IIS and WinRM. A remote, unauthenticated attacker can trigger the flaw by sending specially crafted network packets to a service that listens through http.sys, and reporting indicates WinRM servers are also impacted. Successful exploitation yields remote code execution in the kernel context, with full compromise potential (high confidentiality, integrity and availability impact), consistent with the wormable classification in vendor-adjacent reporting. Affected platforms are Windows 10 versions 2004 and 20H2 and Windows Server versions 2004 and 20H2, which were the current shipping Windows versions at the May 2021 Patch Tuesday release where the fix appeared. The issue is tracked in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-06) and carries a near-certain EPSS exploitation probability (~99.8%), indicating active exploitation in the wild.
What to do: Apply the May 2021 Patch Tuesday security updates for Windows 10 and Windows Server versions 2004 and 20H2, prioritizing internet-facing systems running IIS, WinRM, or other http.sys-based listeners. As an interim mitigation, restrict inbound access to HTTP and WinRM endpoints at the firewall. Confirm remediation by verifying the OS build includes the May 2021 cumulative update, and check the CISA KEV catalog action (apply updates per vendor instructions).
| Microsoft Windows 10 | version 2004 |
| Microsoft Windows 10 | version 20H2 |
| Microsoft Windows Server | version 2004 |
| Microsoft Windows Server | version 20H2 |
| Microsoft HTTP Protocol Stack (http.sys) | as shipped in Windows 10/Windows Server versions 2004 and 20H2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
HTTP Protocol Stack Remote Code Execution Vulnerability
- Affected
- Microsoft HTTP Protocol Stack
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 2004, windows 10 20h2, windows server 2004, windows server 20h2
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H