Vulnerability detail
Enriched intelligence for a single CVE
Critical
CVE-2021-31166
PUBLISHEDHTTP Protocol Stack Remote Code Execution Vulnerability
- Vendor
- Microsoft
- Product
- Windows 10 Version 2004, Windows Server version 2004, Windows 10 Version 20H2, Windows Server version 20H2
- Published
- May 11, 2021
- EPSS
- —
Description
HTTP Protocol Stack Remote Code Execution Vulnerability
CVSS scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Exploitation status
Exploited in the wild
Recorded 2022-04-06 00:00:00 UTC · Source
SSVC decision points
- Exploitation
- active
- Automatable
- Yes
- Technical impact
- total
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| CISA | Apr 06, 2022 |
Potential proof of concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2022-03-07 18:56:52 UTC · 5 stars
CVE-2021-31166: exploitation with Powershell, Python, Ruby, NMAP and Metasploit.
github · Created 2021-10-20 07:37:46 UTC · 2 stars
Just a simple CVE-2021-31166 exploit tool
github · Created 2021-09-27 05:56:45 UTC · 19 stars
Windows HTTP协议栈远程代码执行漏洞 CVE-2021-31166
github · Created 2021-07-03 14:54:59 UTC · 7 stars
Exploit for MS Http Protocol Stack RCE vulnerability (CVE-2021-31166)
github · Created 2021-05-19 07:50:40 UTC · 5 stars
simple bash script for exploit CVE-2021-31166
github · Created 2021-05-17 23:54:12 UTC · 13 stars
HTTP Protocol Stack CVE-2021-31166
github · Created 2021-05-17 19:55:41 UTC · 3 stars
Different rules to detect if CVE-2021-31166 is being exploited
github · Created 2021-05-17 11:12:45 UTC · 9 stars
PoC for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely. Although it was defined as remote command execution, it can only cause the system to crash.
github · Created 2021-05-16 16:15:56 UTC · 823 stars
Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel