CVE-2021-31166criticalunder attackCWE-416

CVE-2021-31166: critical vulnerability in Microsoft Windows 10 Version 2004

HTTP Protocol Stack Remote Code Execution Vulnerability

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 100%
from disclosure to weapon5 days
Published on NVDMay 11
1st PoC+5d
metasploitMay 11
CISA KEV+330d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
22 public exploit(s)
Action required by CISAfederal deadline: 2022-04-27

Apply updates per vendor instructions.

In short

A critical flaw in Windows' HTTP protocol stack allows attackers to execute arbitrary code remotely without authentication. This affects core Windows functionality used by many applications and services.

Technical detail

Use-after-free vulnerability (CWE-416) in the HTTP.sys kernel driver enables remote code execution via specially crafted HTTP requests; no authentication required, with direct kernel-level impact and system compromise.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

HTTP Protocol Stack Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.