HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMicrosoft Windows 7
OSMicrosoftall versionsMicrosoft Windows 8
OSMicrosoftall versionsMicrosoft Windows 8.1
OSMicrosoftall versionsMicrosoft Windows Server 2008
OSMicrosoftr2Microsoft Windows Server 2012
OSMicrosoftr2
CISA KEV — detailsi
- Vendori
- Microsoft ↗
- Producti
- HTTP.sys
- Added to KEVi
- February 10, 2022
- Remediation deadline (US Federal)i
- August 10, 2022(overdue)
Required action (CISA)i
Apply updates per vendor instructions.
CISA descriptioni
Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.
🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
⏰CISA DEADLINE: 10 sierpnia 2022
Tags
RCE
References
Related vulnerabilities
CVE-2025-59287CRITICAL9.8⚠ KEVPL ✓same product
RCE w Windows Server Update Service (WSUS) — deserializacja danych
CVE-2020-1350CRITICAL10.0⚠ KEVPL ✓same product
RCE w Windows DNS Server — krytyczna podatność SIGRed (CVSS 10.0)
CVE-2020-1040CRITICAL9.0⚠ KEVPL ✓same product
RCE w Hyper-V RemoteFX vGPU — błąd walidacji wejścia od gościa
CVE-2020-0646CRITICAL9.8⚠ KEVPL ✓same product
RCE w Microsoft .NET Framework — nieprawidłowa walidacja danych wejściowych
CVE-2019-0708CRITICAL9.8⚠ KEVPL ✓same product
BlueKeep — krytyczny RCE w Remote Desktop Services (RDP)