logo

Major HTTP Vulnerability in Windows Could Lead to Wormable Exploit

ID: 2d17a33c-cd2d-54ae-a144-d23f15effc2f

STIX ID: report--2d17a33c-cd2d-54ae-a144-d23f15effc2f

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2021-05-12

Date Updated: 2026-04-28

Author: Steve Povolny

...
...

Microsoft disclosed CVE-2021-31166, a critical (CVSS 9.8) vulnerability in the HTTP.sys network stack that can cause an unauthenticated remote denial-of-service (BSoD) and may permit remote code execution. The issue affects Windows 10 and Windows Server 2004/20H2, has proof-of-impact potential and simple exploitability, but no confirmed in-the-wild exploitation was reported; the advisory urges immediate patching and McAfee published an IPS signature as a virtual patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.