CVE-2018-8226: High severity Microsoft Windows 10 vulnerability
A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP 2.0 requests, aka "HTTP.sys Denial of Service Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8226?
CVE-2018-8226 is classified as a denial of service vulnerability that can impact availability.
How do I fix CVE-2018-8226?
To fix CVE-2018-8226, ensure that your Windows Server or Windows 10 systems are updated with the latest security patches provided by Microsoft.
What products are affected by CVE-2018-8226?
CVE-2018-8226 affects Windows Server 2016 and various versions of Windows 10, including versions 1607, 1703, 1709, and 1803.
What is the impact of exploiting CVE-2018-8226?
Exploiting CVE-2018-8226 can lead to a denial of service condition, rendering the affected system unresponsive.
Is there a workaround for CVE-2018-8226?
Currently, the best workaround for CVE-2018-8226 is to limit HTTP/2 traffic or implement network filters until a security update can be applied.