PoC released for wormable Windows IIS bug
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-31166 | Use-After-Free RCE in Microsoft Windows HTTP Protocol Stack (http.sys) CVE-2021-31166 is a use-after-free vulnerability (CWE-416) in the Microsoft HTTP Protocol Stack, the kernel-mode HTTP service (http.sys) used by Windows components including IIS and WinRM. A remote, unauthenticated attacker can trigger the flaw by sending specially crafted network packets to a service that listens through http.sys, and reporting indicates WinRM servers are also impacted. Successful exploitation yields remote code execution in the kernel context, with full compromise potential (high confidentiality, integrity and availability impact), consistent with the wormable classification in vendor-adjacent reporting. Affected platforms are Windows 10 versions 2004 and 20H2 and Windows Server versions 2004 and 20H2, which were the current shipping Windows versions at the May 2021 Patch Tuesday release where the fix appeared. The issue is tracked in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-06) and carries a near-certain EPSS exploitation probability (~99.8%), indicating active exploitation in the wild. Do: Apply the May 2021 Patch Tuesday security updates for Windows 10 and Windows Server versions 2004 and 20H2, prioritizing internet-facing systems running IIS, WinRM, or other http.sys-based listeners. As an interim mitigation, restrict inbound access to HTTP and WinRM endpoints at the firewall. Confirm remediation by verifying the OS build includes the May 2021 cumulative update, and check the CISA KEV catalog action (apply updates per vendor instructions). | 9.8 | 100% | KEV |
| masswell over 1,000,000 vulnerable systems (tens of millions of Windows 10 2004/20H2 installs, with likely hundreds of thousands of internet-exposed servers via… |
Full article482 words · extracted from therecord.media · click to collapse
A security researcher has published over the weekend proof-of-concept exploit code for a wormable Windows IIS server vulnerability. Tracked as CVE-2021-31166, the vulnerability was discovered internally by Microsoft's staff and patched last week in the May 2021 Patch Tuesday. Several security researchers and security firms who reviewed last week's security updates considered the bug the most dangerous vulnerability Microsoft fixed in this month's patch cycle. The bug, which received a severity rating of 9.8 out of 10 on the CVSSv3 scale, is a memory corruption vulnerability in the HTTP protocol stack included with recent Windows versions. This stack is used by the Windows built-in IIS server. If this server is enabled, Microsoft says that an attacker can send a malformed packet and execute malicious code right on the operating system kernel. In a security advisory, Microsoft said the bug could be used to create network worms that jump from server to server and recommended "prioritizing the patching of affected servers." But while the bug sounds extremely dangerous, there are also a few mitigation factors. The first is that only recent versions of Windows are impacted. This includes Windows 10 2004 and 20H2, and Windows Server 2004 and 20H2, which basically includes the Windows 10 and Windows Server OS versions released last year, which are very unlikely to have been broadly deployed in production environments. HTTP Protocol Stack Remote Code Execution Vulnerability - CVE-2021-31166 Wormable, RCE, HTTP Protocol IIS Service, CVSS 9.8 > Panic Looking at the list of affected systems, you suddenly start to relax pic.twitter.com/hKAU4XvXuG On Sunday, former Microsoft engineer and current security researcher Axel Souchet released proof-of-concept code for exploiting CVE-2021-31166. The code does not include worming capabilities but only crashes an unpatched Windows system running an IIS server. I've built a PoC for CVE-2021-31166 the "HTTP Protocol Stack Remote Code Execution Vulnerability": https://t.co/8mqLCByvCp pic.twitter.com/yzgUs2CQO5 Nevertheless, the availability of proof-of-concept code is usually the first step towards attackers experimenting with this attack. Even if the number of vulnerable Windows IIS servers might be small, this will not dissuade attackers; which usually take whatever they can get. Microsoft would like to see customers patch their systems. All in all, Microsoft itself is very sensitive to these types of vulnerabilities, especially. In June 2019, a threat actor weaponized an Exim vulnerability to create a worm that spread through the company's Linux-based Azure cloud servers. While Microsoft has most likely patched IIS servers on its Azure infrastructure, there are still other cloud providers and corporate networks where such servers might still be running.
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/poc-released-for-wormable-windows-iis-bug