CVE-2022-35748HighCVSS 7.5

HTTP.sys Denial of Service Vulnerability

Published
August 9, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? In most situations, an unauthenticated attacker could send a specially crafted packet to a targeted server utilizing the Server Name Indication (SNI) over HTTP Protocol Stack (http.sys) to process packets, causing a denial of service (DOS).

🎯 Affected products11

  • Windows Server 2012
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2012 R2
  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2016
  • Windows Server 2016 (Server Core installation)
  • Windows Server 2019
  • Windows Server 2019 (Server Core installation)
  • Windows Server 2022
  • Windows Server 2022 (Server Core installation)
  • Windows Server, version 20H2 (Server Core Installation)

✅ Remediation

KB5016623 (Security Update) — fixed build 10.0.17763.3287 KB5016627 (Security Update) — fixed build 10.0.20348.887 KB5016616 (Security Update) — fixed build 10.0.19042.1889 KB5016622 (Security Update) — fixed build 10.0.14393.5291 KB5016672 (Monthly Rollup) — fixed build 6.2.9200.23817 KB5016684 (Security Only) — fixed build 6.2.9200.23817 KB5016681 (Monthly Rollup) — fixed build 6.3.9600.20520 KB5016683 (Security Only) — fixed build 6.3.9600.20520

🔗 References (12)