CVE-2021-31166CISA KEV
Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
- Product
- HTTP Protocol Stack
- Added to KEV
- 6 Apr 2022
- Federal remediation due
- 27 Apr 2022
- Known ransomware use
- Not reported