First published: Tue May 11 2021(Updated: )
HTTP Protocol Stack Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft HTTP Protocol Stack | ||
Microsoft Windows 10 | <10.0.19041.982 | |
Microsoft Windows 10 | <10.0.19042.982 | |
Microsoft Windows Server 2004 | <10.0.19041.982 | |
Microsoft Windows Server 20H2 | <10.0.19042.982 | |
Windows 10 | =20h2 | |
Windows 10 | =2004 | |
Microsoft Windows Server 2016 | =20h2 | |
Microsoft Windows Server 2016 | =2004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31166 has a critical severity rating due to its potential for remote code execution.
To fix CVE-2021-31166, Microsoft recommends applying the latest security updates for affected Windows operating systems.
CVE-2021-31166 affects Microsoft Windows 10 versions 20H2 and 2004, as well as Windows Server 2016.
Yes, CVE-2021-31166 can be exploited remotely, allowing attackers to execute arbitrary code on vulnerable systems.
CVE-2021-31166 specifically involves the Microsoft HTTP Protocol Stack and the http.sys driver.