CVE-2021-31166

9.8CRITICAL

HTTP Protocol Stack Remote Code Execution Vulnerability

Published: 5/11/2021Updated: 10/30/2025

CISA Known Exploited Vulnerability

Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

Due Date:

2022-04-27

Description

HTTP Protocol Stack Remote Code Execution Vulnerability

AI AnalysisPowered by AI

Affected Products

microsoftwindows_10_2004
microsoftwindows_10_20h2
microsoftwindows_server_2004
microsoftwindows_server_20h2

References