CVE-2023-35298HighCVSS 7.5
HTTP.sys Denial of Service Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? In most situations, an unauthenticated attacker could send a specially crafted packet to a targeted server utilizing the Server Name Indication (SNI) over HTTP Protocol Stack (http.sys) to process packets, causing a denial of service (DOS).
🎯 Affected products6
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 11 version 21H2 for ARM64-based Systems
- Windows 11 version 21H2 for x64-based Systems
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
✅ Remediation
KB5028171 (Security Update) — fixed build 10.0.20348.1850 KB5028182 (Security Update) — fixed build 10.0.22000.2176 KB5028185 (Security Update) — fixed build 10.0.22621.1992
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35298
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028171
- referencehttps://support.microsoft.com/help/5028171
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028182
- referencehttps://support.microsoft.com/help/5028182
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028185
- referencehttps://support.microsoft.com/help/5028185