← back
CVE-2022-21907criticalobserved exploitation

HTTP Protocol Stack Remote Code Execution Vulnerability

97Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 9.8epss 93%
from disclosure to weapon0 days
Published on NVDJan 11
1st PoCJan 11
VulnCheck+847d
exploitation probability
93%top 1% of all CVEs
observed exploitation
yesVulnCheck
31 public exploit(s)
HTTP Protocol Stack Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
public PoCs found31
exploitdbwww.exploit-db.com/exploits/51575unverifiedgithubgithub.com/ZZ-SOCMAP/CVE-2022-21907361githubgithub.com/polakow/CVE-2022-21907128githubgithub.com/p0dalirius/CVE-2022-21907-http.sys83githubgithub.com/michelep/CVE-2022-21907-Vulnerability-PoC29githubgithub.com/mauricelambert/CVE-2022-2190726githubgithub.com/Malwareman007/CVE-2022-2190717githubgithub.com/0xmaximus/Home-Demolisher8githubgithub.com/corelight/cve-2022-219075githubgithub.com/gpiechnik2/nmap-CVE-2022-219072githubgithub.com/iveresk/cve-2022-21907-http.sys1githubgithub.com/kamal-marouane/CVE-2022-219071githubgithub.com/iveresk/cve-2022-219071githubgithub.com/siboy17/CVE-2022-21907-http.sys0githubgithub.com/EzoomE/CVE-2022-21907-RCE0githubgithub.com/cassie0206/CVE-2022-219070githubgithub.com/asepsaepdin/CVE-2022-219070vulncheckvulncheck.com/xdb/167adf17e68cunverifiedvulncheckvulncheck.com/xdb/79c1d5825bd3unverifiedvulncheckvulncheck.com/xdb/1306e5fc35fbunverifiedvulncheckvulncheck.com/xdb/f31e1149e743unverifiedvulncheckvulncheck.com/xdb/837d27449c0aunverifiedvulncheckvulncheck.com/xdb/8444bab2f56funverifiedvulncheckvulncheck.com/xdb/86fb978ad867unverifiedvulncheckvulncheck.com/xdb/65a99dd97dd6unverifiedvulncheckvulncheck.com/xdb/2590a1a4a8efunverifiedcve_referencepacketstormsecurity.com/files/166730/Microsoft-HTTP-Protocol-Stack-Denial-Of-Service.htmlunverifiedvulncheckvulncheck.com/xdb/9e5b11d4061dunverifiedvulncheckvulncheck.com/xdb/d5f3de9489d0unverifiedvulncheckvulncheck.com/xdb/8d7c3f5c3e4cunverifiedvulncheckvulncheck.com/xdb/bb7d8819859eunverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.