First published: Thu Apr 12 2018(Updated: )
A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP 2.0 requests, aka "HTTP.sys Denial of Service Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1511 | |
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1703 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | =1709 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0956 is classified as a denial of service vulnerability that can cause significant disruption in services.
To fix CVE-2018-0956, apply the latest security updates provided by Microsoft for the affected Windows versions.
CVE-2018-0956 affects Microsoft Windows 10 and Windows Server 2016 across multiple versions.
CVE-2018-0956 exploits improper parsing of specially crafted HTTP 2.0 requests by the HTTP.sys protocol stack.
Exploitation of CVE-2018-0956 can lead to service downtime and disruption of web applications running on affected systems.