CRITICAL

CVE-2021-31166

Microsoft Windows 10 2004 2021-05-11 CVSS v3.1
CVSS
9.8
KEV

Description

HTTP Protocol Stack Remote Code Execution Vulnerability

Summary dbcve.org

A remote code execution vulnerability exists in the HTTP Protocol Stack (http.sys) with critical severity (CVSS 9.8). The vulnerability allows remote attackers to execute arbitrary code via specially crafted HTTP requests.

Mitigation

Apply Microsoft security updates for CVE-2021-31166; ensure Windows Server and IIS deployments are patched. If patching is delayed, consider restricting exposure to untrusted networks.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

99.77%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE