CRITICAL
CVE-2021-31166
CVSS
9.8
KEV
Description
HTTP Protocol Stack Remote Code Execution Vulnerability
Summary dbcve.org
A remote code execution vulnerability exists in the HTTP Protocol Stack (http.sys) with critical severity (CVSS 9.8). The vulnerability allows remote attackers to execute arbitrary code via specially crafted HTTP requests.
Mitigation
Apply Microsoft security updates for CVE-2021-31166; ensure Windows Server and IIS deployments are patched. If patching is delayed, consider restricting exposure to untrusted networks.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
99.77%
Probability of exploitation in next 30 days
100th percentile
References
http://packetstormsecurity.com/files/162722/Microsoft-HTTP-Protocol-Stack-Remote-Code-Execution.html
Third Party Advisory, VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31166
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-31166
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.