CVE-2021-31166: critical vulnerability in Microsoft Windows 10 Version 2004
HTTP Protocol Stack Remote Code Execution Vulnerability
Published · Updated
100Vexday Risk Score
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
ssvc Actcvss 9.8epss 100%
from disclosure to weapon5 days
Published on NVDMay 11
1st PoC+5d
metasploitMay 11
CISA KEV+330d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
22 public exploit(s)
Action required by CISAfederal deadline: 2022-04-27
Apply updates per vendor instructions.
In short
A critical flaw in Windows' HTTP protocol stack allows attackers to execute arbitrary code remotely without authentication. This affects core Windows functionality used by many applications and services.
Technical detail
Use-after-free vulnerability (CWE-416) in the HTTP.sys kernel driver enables remote code execution via specially crafted HTTP requests; no authentication required, with direct kernel-level impact and system compromise.
Summary generated and translated by AI from the official description.
The full analysis of this CVE is available in Portuguese →
HTTP Protocol Stack Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected products
Microsoft · Windows 10 Version 2004Microsoft · Windows 10 Version 20H2Microsoft · Windows Server version 2004Microsoft · Windows Server version 20H2public PoCs found — 22
githubgithub.com/0vercl0k/CVE-2021-31166★ 827githubgithub.com/ZZ-SOCMAP/CVE-2021-31166★ 19githubgithub.com/corelight/CVE-2021-31166★ 12githubgithub.com/zha0gongz1/CVE-2021-31166★ 8githubgithub.com/0xmaximus/Home-Demolisher★ 8githubgithub.com/y0g3sh-99/CVE-2021-31166-Exploit★ 7githubgithub.com/zecopro/CVE-2021-31166★ 5githubgithub.com/mvlnetdev/CVE-2021-31166-detection-rules★ 3githubgithub.com/iranzai/CVE-2021-31166-exploit★ 2githubgithub.com/bgsilvait/WIn-CVE-2021-31166★ 0vulncheckvulncheck.com/xdb/3d89c1c29c99unverifiedcve_referencepacketstormsecurity.com/files/162722/Microsoft-HTTP-Protocol-Stack-Remote-Code-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/e7beeee5920bunverifiedvulncheckvulncheck.com/xdb/3dbf2e48a531unverifiedvulncheckvulncheck.com/xdb/4e55ff328292unverifiedvulncheckvulncheck.com/xdb/e1866d71c3afunverifiedvulncheckvulncheck.com/xdb/b60f189b7005unverifiedvulncheckvulncheck.com/xdb/86c76b7eb3bcunverifiedvulncheckvulncheck.com/xdb/5719bfcb7a63unverifiedvulncheckvulncheck.com/xdb/e25c79214978unverifiedvulncheckvulncheck.com/xdb/74d91688925dunverifiedvulncheckvulncheck.com/xdb/a07dc76a6f89unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — Microsoft Windows 10 Version 2004
In the same product, most dangerous first.
CVE-2021-34527HIGHWindows Print Spooler Remote Code Execution VulnerabilityEPSS 99.8%KEVCVE-2020-1472MEDIUMNetlogon Elevation of Privilege VulnerabilityEPSS 99.4%KEVCVE-2022-30190HIGHMicrosoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution VulnerabilityEPSS 99.2%KEVCVE-2021-40444HIGHMicrosoft MSHTML Remote Code Execution VulnerabilityEPSS 97.5%KEVCVE-2021-1675HIGHWindows Print Spooler Remote Code Execution VulnerabilityEPSS 85.3%KEVCVE-2022-26923HIGHActive Directory Domain Services Elevation of Privilege VulnerabilityEPSS 83.5%KEV