CVE-2016-0150High

HTTP.sys Denial of Service Vulnerability

Published
April 12, 2016
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP 2.0 requests. An attacker who successfully exploited the vulnerability could create a denial of service condition, causing the target system to become unresponsive. To exploit this vulnerability, an attacker could send a specially crafted HTTP packet to a target system, causing the affected system to become nonresponsive. The update addresses the vulnerability by modifying how the Windows HTTP protocol stack handles HTTP 2.0 requests. Note that the denial of service vulnerability would not allow an attacker to execute code or to elevate user rights.

🎯 Affected products4

  • Windows 10 Version 1511 for 32-bit Systems
  • Windows 10 Version 1511 for x64-based Systems
  • Windows 10 for 32-bit Systems
  • Windows 10 for x64-based Systems

✅ Remediation

KB3147461 (Security Update) KB3147458 (Security Update)

🔗 References (3)