CVE-2021-31166: HTTP Protocol Stack Remote Code Execution Vulnerability
Published May 11, 2021
·Updated
HTTP Protocol Stack Remote Code Execution Vulnerability
Other sources
Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
— CISA
Affected Software
9 affected components
Microsoft HTTP Protocol Stack
Microsoft Windows 10 2004<10.0.19041.982
Microsoft Windows 10 20h2<10.0.19042.982
Microsoft Windows Server 2004<10.0.19041.982
Microsoft Windows Server 20h2<10.0.19042.982
Microsoft Windows 10=20h2
Microsoft Windows 10=2004
Microsoft Windows Server 2016=20h2
Microsoft Windows Server 2016=2004
Remediation
Event History
May 11, 2021
CVE Published
via MITRE·07:11 PM
Data Sourced
via MITRE·07:11 PM
DescriptionSeverity
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 6, 2022
Known Exploited
via CISA·12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2021-31166?
CVE-2021-31166 has a critical severity rating due to its potential for remote code execution.
2
How do I fix CVE-2021-31166?
To fix CVE-2021-31166, Microsoft recommends applying the latest security updates for affected Windows operating systems.
3
What systems are affected by CVE-2021-31166?
CVE-2021-31166 affects Microsoft Windows 10 versions 20H2 and 2004, as well as Windows Server 2016.
4
Can CVE-2021-31166 be exploited remotely?
Yes, CVE-2021-31166 can be exploited remotely, allowing attackers to execute arbitrary code on vulnerable systems.
5
What components are involved in CVE-2021-31166?
CVE-2021-31166 specifically involves the Microsoft HTTP Protocol Stack and the http.sys driver.