CVE-2021-31166
9.8CRITICALHTTP Protocol Stack Remote Code Execution Vulnerability
Published: 5/11/2021Updated: 10/30/2025
CISA Known Exploited Vulnerability
Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
Required Action:
Apply updates per vendor instructions.
Due Date:
2022-04-27
Description
HTTP Protocol Stack Remote Code Execution Vulnerability
AI AnalysisPowered by AI
Affected Products
microsoftwindows_10_2004
microsoftwindows_10_20h2
microsoftwindows_server_2004
microsoftwindows_server_20h2
References
- http://packetstormsecurity.com/files/162722/Microsoft-HTTP-Protocol-Stack-Remote-Code-Execution.htmlThird Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31166PatchVendor Advisory
- http://packetstormsecurity.com/files/162722/Microsoft-HTTP-Protocol-Stack-Remote-Code-Execution.htmlThird Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31166PatchVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-31166US Government Resource