HTTP Protocol Stack Remote Code Execution Vulnerability
Loading...
Loading...
Score elevated to 9.8 because EPSS predicts 92% probability of exploitation within the next 30 days (top 0.3% of all CVEs). NVD baseline CVSS 9.8 retained for reference. Confidence: see factors.
HTTP Protocol Stack Remote Code Execution Vulnerability
January 11, 2022
November 21, 2024
Security Update Guide - Microsoft Security Response Center. Patch available via Microsoft Security Update
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-21907Security Update Guide - Microsoft Security Response Center. Patch available via Microsoft Security Update
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21907Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Working exploit code is in the public domain (9 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution
Open source ↗PoC for CVE-2021-31166 and CVE-2022-21907
Open source ↗POC for CVE-2022-21907: HTTP Protocol Stack Remote Code Execution Vulnerability.
Open source ↗Repository containing nse script for vulnerability CVE-2022-21907. It is a component (IIS) vulnerability on Windows. It allows remote code execution. The vulnerability affects the kernel module http. sys, which handles most basic IIS operations.
Open source ↗A REAL DoS exploit for CVE-2022-21907
Open source ↗CVE-2022-21907 Vulnerability PoC
Open source ↗HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907
Open source ↗Proof of concept of CVE-2022-21907 Double Free in http.sys driver, triggering a kernel crash on IIS servers
Open source ↗CVE-2022-21907: detection, protection, exploitation and demonstration. Exploitation: Powershell, Python, Ruby, NMAP and Metasploit. Detection and protection: Powershell. Demonstration: Youtube.
Open source ↗cve-2022-21907
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2022-21907
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.
msrc