Major HTTP Vulnerability in Windows Could Lead to Wormable Exploit
ID: 2d17a33c-cd2d-54ae-a144-d23f15effc2f
STIX ID: report--2d17a33c-cd2d-54ae-a144-d23f15effc2f
Feed Name: McAfee Labs Blog
Threat Score
Microsoft disclosed CVE-2021-31166, a critical (CVSS 9.8) vulnerability in the HTTP.sys network stack that can cause an unauthenticated remote denial-of-service (BSoD) and may permit remote code execution. The issue affects Windows 10 and Windows Server 2004/20H2, has proof-of-impact potential and simple exploitability, but no confirmed in-the-wild exploitation was reported; the advisory urges immediate patching and McAfee published an IPS signature as a virtual patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
