CVE-2021-31166
published 2021-05-11CVE-2021-31166: HTTP Protocol Stack Remote Code Execution Vulnerability
PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-04-27
Exploited in the wild
EPSS
99.66%
99.9th percentile
HTTP Protocol Stack Remote Code Execution Vulnerability
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_2004 | < 10.0.19041.982 | 10.0.19041.982 |
| microsoft | windows_10_20h2 | < 10.0.19042.982 | 10.0.19042.982 |
| microsoft | windows_10_version_2004 | >= 10.0.0 < 10.0.19041.982 | 10.0.19041.982 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.982 | 10.0.19042.982 |
| microsoft | windows_server_2004 | < 10.0.19041.982 | 10.0.19041.982 |
| microsoft | windows_server_20h2 | < 10.0.19042.982 | 10.0.19042.982 |
| microsoft | windows_server_version_2004 | >= 10.0.0 < 10.0.19041.982 | 10.0.19041.982 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19042.982 | 10.0.19042.982 |
| msrc | windows_10_version_2004_for_32-bit_systems | — | — |
| msrc | windows_10_version_2004_for_arm64-based_systems | — | — |
| msrc | windows_10_version_2004_for_x64-based_systems | — | — |
| msrc | windows_10_version_20h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_20h2_for_arm64-based_systems | — | — |
| msrc | windows_server_version_2004 | — | — |
| msrc | windows_server_version_20h2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
other1010949 - Microsoft Windows HTTP Protocol Stack Remote Code Execution Vulnerability (CVE-2021-31166)↗
snort↗
57539, 57540, 57542 – 57545, 57548 - 57550
snort↗
57539, 57540, 57542 - 57545, 57548 - 57550
- →CVE-2021-31166 is exploitable by sending a single specially crafted packet to an HTTP server; no authentication or user interaction required — monitor for malformed/unexpected HTTP.sys-level requests on Windows HTTP servers. ↗
- →Windows 10 client machines configured as web servers are also in scope — expand detection coverage beyond server-class systems to any Windows 10 host running HTTP.sys. ↗
- →Any organization using HTTP.sys protocol stack should be treated as a high-priority detection target; absence of authentication requirement makes exploit attempts indistinguishable from normal unauthenticated HTTP traffic without deep packet inspection. ↗
- ·Snort rules 57539, 57540, 57542–57545, 57548–57550 are subject to change; Firepower/SRU customers should ensure they are running the latest ruleset update. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_msrc9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3mj9-c62w-jw5w: HTTP Protocol Stack Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-31166 [CRITICAL] CWE-416 GHSA-3mj9-c62w-jw5w: HTTP Protocol Stack Remote Code Execution Vulnerability
HTTP Protocol Stack Remote Code Execution Vulnerability
VulnCheck
Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability
vulncheck·2021·CVSS 9.8
CVE-2021-31166 [CRITICAL] CWE-416 Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability
Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability
Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
Affected: Microsoft HTTP Protocol Stack
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/reports/2022-unit42-ransomware-threat-report-final.pdf; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://static.tenable.com/marketing/whitepapers/Whitepaper-Ransomware_Ecosystem.pdf
Exploit PoC: https://vulncheck.com/xdb/3dbf2e48a531; https://vulncheck.com/xdb/4e55ff328292; https://vulncheck.com/xdb/e1866d71c3af; https://vulncheck.com/xdb/b60f189b7005;
CISA
Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability
cisa·2022-04-06·CVSS 9.8
CVE-2021-31166 [CRITICAL] CWE-416 Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability
Vulnerability: Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability
Affected: Microsoft HTTP Protocol Stack
Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-31166
Remediation Due Date: 2022-04-27
Microsoft
HTTP Protocol Stack Remote Code Execution Vulnerability
vendor_msrc·2021-05-11·CVSS 9.8
CVE-2021-31166 [CRITICAL] HTTP Protocol Stack Remote Code Execution Vulnerability
HTTP Protocol Stack Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
In most situations, an unauthenticated attacker could send a specially crafted packet to a targeted server utilizing the HTTP Protocol Stack (http.sys) to process packets.
Is this wormable?
Yes. Microsoft recommends prioritizing the patching of affected servers.
Windows HTTP.sys: Windows HTTP.sys
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5003173
Reference: https://support.microsoft.com/help/5003173
Suricata
ET EXPLOIT Windows HTTP Protocol Stack UAF/RCE (CVE-2021-31166), http.sys DOS (CVE-2022-21907) Inbound
suricata·2021-05-17·CVSS 9.8
CVE-2021-31166 [CRITICAL] ET EXPLOIT Windows HTTP Protocol Stack UAF/RCE (CVE-2021-31166), http.sys DOS (CVE-2022-21907) Inbound
ET EXPLOIT Windows HTTP Protocol Stack UAF/RCE (CVE-2021-31166), http.sys DOS (CVE-2022-21907) Inbound
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Windows HTTP Protocol Stack UAF/RCE (CVE-2021-31166), http.sys DOS (CVE-2022-21907) Inbound"; flow:established,to_server; http.accept_enc; content:",|20|,"; fast_pattern; reference:url,github.com/0vercl0k/CVE-2021-31166; reference:cve,2021-31166; classtype:attempted-admin; sid:2032962; rev:1; metadata:attack_target Server, created_at 2021_05_17, cve CVE_2021_31166, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_05_17, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Publ
Exploit-DB
Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution
exploitdb·2023-07-07·CVSS 9.8
CVE-2022-21907 [CRITICAL] Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution
Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution
---
## Title: Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution
## Author: nu11secur1ty
## Date: 01.14.2022
## Vendor: https://www.microsoft.com/
## Software: https://www.microsoft.com/en-us/download/details.aspx?id=48264
## Reference: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-21907
## CVE-2022-21907
## Description:
NOTE: After a couple of hours of tests and experiments, I found that
there have been no vulnerabilities, this is just a ridiculous
experiment of Microsoft. When I decided to install the IIS packages on
these Windows platforms, everything was ok, and everything is patched!
Windows Server 2019, Windows 10 version 1809 - 2018 year are not
vulnerable by default, but after I decide
Metasploit
Windows IIS HTTP Protocol Stack DOS
metasploit·CVSS 9.8
CVE-2021-31166 [CRITICAL] Windows IIS HTTP Protocol Stack DOS
Windows IIS HTTP Protocol Stack DOS
This module exploits CVE-2021-31166, a UAF bug in http.sys when parsing specially crafted Accept-Encoding headers that was patched by Microsoft in May 2021, on vulnerable IIS servers. Successful exploitation will result in the target computer BSOD'ing before subsequently rebooting. Note that the target IIS server may or may not come back up, this depends on the target's settings as to whether IIS is configured to start on reboot.
Securelist
IT threat evolution in Q2 2021. PC statistics
blogs_securelist·2021-08-12
IT threat evolution in Q2 2021. PC statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Ransomware programs
Quarterly trends and highlights
Attack on Colonial Pipeline and closure of DarkSide
Closure of Avaddon
Clash with Clop
Attacks on NAS devices
Number of new ransomware modifications
Number of users attacked by ransomware Trojans
Geography of ransomware attacks
Top 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by cybercriminals during cyberattacks
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
Countries that serve as sources of web-based attacks: Top 10
Countries where users fa
Securelist
IT threat evolution in Q2 2021. PC statistics
blogs_securelist·2021-08-12
IT threat evolution in Q2 2021. PC statistics
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by cybercriminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
These statistics are based on detection verdicts of Kaspersky products received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q2 2021:
- Kaspersky solutions blocked 1,686,025,551 attacks from online resources across the globe.
- Web antivirus recognized 675,832,360 unique URLs as malicious.
- Attempts to run malware for stealing money from online bank accounts were stopped on the computers of 119,252 unique users.
- Ransomware attacks were defeated on the computers
Checkpoint
17th May – Threat Intelligence Report
blogs_checkpoint·2021-05-17
CVE-2021-31166 17th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 17th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 17th May, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Ireland’s Health Services Executive (HSE), a provider of health and social services, among them Covid-19 vaccines, has suffered an attack by Conti ransomware, forcing it to shut down its IT systems. Vaccine appointments have not been affected, however other hospital services might be affected.
Check Point SandBlast and Harmony E
Talos
Threat Source Newsletter (May 13, 2021)
blogs_talos·2021-05-13
Threat Source Newsletter (May 13, 2021)
## Threat Source Newsletter (May 13, 2021)
Newsletter compiled by Jon Munshaw.
Good afternoon, Talos readers.
In case you missed the Friday news drop last week, we have an update on the Lemon Duck cryptocurrency miner. It's not as eye-catching as the ransomware attacks that make the news, but Lemon Duck's exploitation of Microsoft Exchange servers shows that patching is still king, and a cryptocurrency attack shows there's room for additional attacks in the future.
Speaking of patching, it's time to update your Microsoft products if you haven't already. This month's Patch Tuesday included a wormable vulnerability in the HTTP protocol stack that has a severity score of 9.8 out of 10. Of course, it's important to always patch any and all vulnerabilities, but that's the one that most peop
Talos
Threat Source Newsletter (May 13, 2021)
blogs_talos·2021-05-13
Threat Source Newsletter (May 13, 2021)
Newsletter compiled by Jon Munshaw.
Good afternoon, Talos readers.
In case you missed the Friday news drop last week, we have an update on the Lemon Duck cryptocurrency miner. It's not as eye-catching as the ransomware attacks that make the news, but Lemon Duck's exploitation of Microsoft Exchange servers shows that patching is still king, and a cryptocurrency attack shows there's room for additional attacks in the future.
Speaking of patching, it's time to update your Microsoft products if you haven't already. This month's Patch Tuesday included a wormable vulnerability in the HTTP protocol stack that has a severity score of 9.8 out of 10. Of course, it's important to always patch any and all vulnerabilities, but that's the one that most people came out of Tuesday talking about.
## Up
Trendmicro
May Patch Tuesday Offers Relative Respite
blogs_trendmicro·2021-05-11·CVSS 9.8
[CRITICAL] May Patch Tuesday Offers Relative Respite
Ausnutzung von Schwachstellen
## May Patch Tuesday Offers Relative Respite
Compared to the previous months of 2021, this month’s Patch Tuesday cycle is a slight lull. Only 55 vulnerabilities were fixed this month, with only four of these classified as Critical.
By: Trend Micro May 11, 2021 Read time: ( words)
Save to Folio
Compared to the previous months of 2021, this month’s Patch Tuesday cycle is a slight lull. Only 55 vulnerabilities were fixed this month, with only four of these classified as Critical. One fell under the rarely used Moderate category, while the remaining 50 were classified as Important. A significant number of these vulnerabilities — 13 in total — were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: HTTP Protocol Stack Vulnerability
The mo
Talos
Microsoft Patch Tuesday for May 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-05-11·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday for May 2021 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for May 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Chris Neal.
Microsoft released its monthly security update Tuesday, disclosing 55 vulnerabilities across its suite of products, the fewest in any month since January 2020.
There are only three critical vulnerabilities patched in this month, while two are of “moderate” severity and the rest are “important.” All three critical vulnerabilities, however, are considered "more likely” to be exploited, according to Microsoft.
This month’s security update provides patches for several major pieces of software, including Microsoft Office, SharePoint and Windows’ wireless networking. For a full rundown of these CVEs, head to Microsoft’s security update page .
Talos also rel
Krebs
Microsoft Patch Tuesday, May 2021 Edition
blogs_krebs·2021-05-11·CVSS 7.5
[HIGH] Microsoft Patch Tuesday, May 2021 Edition
Microsoft today released fixes to plug at least 55 security holes in its Windows operating systems and other software. Four of these weaknesses can be exploited by malware and malcontents to seize complete, remote control over vulnerable systems without any help from users. On deck this month are patches to quash a wormable flaw, a creepy wireless bug, and yet another reason to call for the death of Microsoft’s Internet Explorer (IE) web browser.
While May brings about half the normal volume of updates from Microsoft, there are some notable weaknesses that deserve prompt attention, particularly from enterprises. By all accounts, the most pressing priority this month is CVE-2021-31166 , a Windows 10 and Windows Server flaw which allows an unauthenticated attacker to remotely execute malici
Tenable
Microsoft’s May 2021 Patch Tuesday Addresses 55 CVEs (CVE-2021-31166)
blogs_tenable·2021-05-11·CVSS 9.8
[CRITICAL] Microsoft’s May 2021 Patch Tuesday Addresses 55 CVEs (CVE-2021-31166)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Microsoft & Adobe Patch Tuesday (May 2021) – Qualys covers 85 Vulnerabilities, 26 Critical
blogs_qualys·2021-05-11·CVSS 9.9
CVE-2021-31181 [CRITICAL] Microsoft & Adobe Patch Tuesday (May 2021) – Qualys covers 85 Vulnerabilities, 26 Critical
## Microsoft Patch Tuesday – May 2021
Microsoft patched 55 CVEs in their May 2021 Patch Tuesday release, of which 4 are rated as critical severity. Three 0-day vulnerability patches were included in the release. As of this publication date, none have been exploited.
Qualys released 12 QIDs on the same day, providing vulnerability detection and patch management coverage (where applicable) for all 55 CVEs and the related KBs.
## Critical Microsoft vulnerabilities patched:
CVE-2021-31181 – SharePoint Remote Code Execution Vulnerability
Microsoft released patches addressing a critical RCE vulnerability in SharePoint (CVE-2021-31181). This CVE has a high likelihood of exploitability and is assigned a CVSSv3 base score of 8.8 by the vendor.
CVE-2021-31166 – HTTP Protocol Stack Remote Code
Trendmicro
May Patch Tuesday Offers Relative Respite
blogs_trendmicro·2021-05-11·CVSS 9.8
[CRITICAL] May Patch Tuesday Offers Relative Respite
Exploits & Vulnerabilities
# May Patch Tuesday Offers Relative Respite
Compared to the previous months of 2021, this month’s Patch Tuesday cycle is a slight lull. Only 55 vulnerabilities were fixed this month, with only four of these classified as Critical.
By: Trend Micro
2021/05/11
Read time: ( words)
Save to Folio
Compared to the previous months of 2021, this month’s Patch Tuesday cycle is a slight lull. Only 55 vulnerabilities were fixed this month, with only four of these classified as Critical. One fell under the rarely used Moderate category, while the remaining 50 were classified as Important. A significant number of these vulnerabilities — 13 in total — were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: HTTP Protocol Stack Vulnerability
The most se
Trendmicro
May Patch Tuesday Offers Relative Respite
blogs_trendmicro·2021-05-11·CVSS 9.8
[CRITICAL] May Patch Tuesday Offers Relative Respite
Sfruttamento vulnerabilità
## May Patch Tuesday Offers Relative Respite
Compared to the previous months of 2021, this month’s Patch Tuesday cycle is a slight lull. Only 55 vulnerabilities were fixed this month, with only four of these classified as Critical.
By: Trend Micro May 11, 2021 Read time: ( words)
Save to Folio
Compared to the previous months of 2021, this month’s Patch Tuesday cycle is a slight lull. Only 55 vulnerabilities were fixed this month, with only four of these classified as Critical. One fell under the rarely used Moderate category, while the remaining 50 were classified as Important. A significant number of these vulnerabilities — 13 in total — were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: HTTP Protocol Stack Vulnerability
The most
Talos
Microsoft Patch Tuesday for May 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-05-11·CVSS 7.5
[HIGH] Microsoft Patch Tuesday for May 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Chris Neal.
Microsoft released its monthly security update Tuesday, disclosing 55 vulnerabilities across its suite of products, the fewest in any month since January 2020.
There are only three critical vulnerabilities patched in this month, while two are of “moderate” severity and the rest are “important.” All three critical vulnerabilities, however, are considered "more likely” to be exploited, according to Microsoft.
This month’s security update provides patches for several major pieces of software, including Microsoft Office, SharePoint and Windows’ wireless networking. For a full rundown of these CVEs, head to Microsoft’s security update page.
Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilitie
Trendmicro
May Patch Tuesday Offers Relative Respite
blogs_trendmicro·2021-05-11·CVSS 9.8
[CRITICAL] May Patch Tuesday Offers Relative Respite
Exploits & Vulnerabilities
## May Patch Tuesday Offers Relative Respite
Compared to the previous months of 2021, this month’s Patch Tuesday cycle is a slight lull. Only 55 vulnerabilities were fixed this month, with only four of these classified as Critical.
By: Trend Micro May 11, 2021 Read time: ( words)
Save to Folio
Compared to the previous months of 2021, this month’s Patch Tuesday cycle is a slight lull. Only 55 vulnerabilities were fixed this month, with only four of these classified as Critical. One fell under the rarely used Moderate category, while the remaining 50 were classified as Important. A significant number of these vulnerabilities — 13 in total — were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: HTTP Protocol Stack Vulnerability
The most
Trendmicro
May Patch Tuesday Offers Relative Respite
blogs_trendmicro·2021-05-11·CVSS 9.8
[CRITICAL] May Patch Tuesday Offers Relative Respite
Exploits & Vulnerabilities
## May Patch Tuesday Offers Relative Respite
Compared to the previous months of 2021, this month’s Patch Tuesday cycle is a slight lull. Only 55 vulnerabilities were fixed this month, with only four of these classified as Critical.
By: Trend Micro 2021/05/11 Read time: ( words)
Save to Folio
Compared to the previous months of 2021, this month’s Patch Tuesday cycle is a slight lull. Only 55 vulnerabilities were fixed this month, with only four of these classified as Critical. One fell under the rarely used Moderate category, while the remaining 50 were classified as Important. A significant number of these vulnerabilities — 13 in total — were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: HTTP Protocol Stack Vulnerability
The most se
Krebs
Microsoft Patch Tuesday, May 2021 Edition
blogs_krebs·2021-05-11·CVSS 7.5
[HIGH] Microsoft Patch Tuesday, May 2021 Edition
Microsoft today released fixes to plug at least 55 security holes in its Windows operating systems and other software. Four of these weaknesses can be exploited by malware and malcontents to seize complete, remote control over vulnerable systems without any help from users. On deck this month are patches to quash a wormable flaw, a creepy wireless bug, and yet another reason to call for the death of Microsoft’s Internet Explorer (IE) web browser.
While May brings about half the normal volume of updates from Microsoft, there are some notable weaknesses that deserve prompt attention, particularly from enterprises. By all accounts, the most pressing priority this month is CVE-2021-31166, a Windows 10 and Windows Server flaw which allows an unauthenticated attacker to remotely execute malicio
Qualys
Microsoft & Adobe Patch Tuesday (May 2021) - Qualys covers 85 Vulnerabilities, 26 Critical | Qualys
blogs_qualys·2021-05-11·CVSS 9.9
CVE-2021-31181 [CRITICAL] Microsoft & Adobe Patch Tuesday (May 2021) - Qualys covers 85 Vulnerabilities, 26 Critical | Qualys
### Microsoft Patch Tuesday – May 2021
Microsoft patched 55 CVEs in their May 2021 Patch Tuesday release, of which 4 are rated as critical severity. Three 0-day vulnerability patches were included in the release. As of this publication date, none have been exploited.
Qualys released 12 QIDs on the same day, providing vulnerability detection and patch management coverage (where applicable) for all 55 CVEs and the related KBs.
#### Critical Microsoft vulnerabilities patched:
CVE-2021-31181 – SharePoint Remote Code Execution Vulnerability
Microsoft released patches addressing a critical RCE vulnerability in SharePoint (CVE-2021-31181). This CVE has a high likelihood of exploitability and is assigned a CVSSv3 base score of 8.8 by the vendor.
CVE-2021-31166 – HTTP Protocol Stack Remote Co
Trendmicro
May Patch Tuesday Offers Relative Respite
blogs_trendmicro·2021-05-11·CVSS 9.8
[CRITICAL] May Patch Tuesday Offers Relative Respite
Exploits y vulnerabilidades
## May Patch Tuesday Offers Relative Respite
Compared to the previous months of 2021, this month’s Patch Tuesday cycle is a slight lull. Only 55 vulnerabilities were fixed this month, with only four of these classified as Critical.
By: Trend Micro May 11, 2021 Read time: ( words)
Save to Folio
Compared to the previous months of 2021, this month’s Patch Tuesday cycle is a slight lull. Only 55 vulnerabilities were fixed this month, with only four of these classified as Critical. One fell under the rarely used Moderate category, while the remaining 50 were classified as Important. A significant number of these vulnerabilities — 13 in total — were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: HTTP Protocol Stack Vulnerability
The most
Crowdstrike
May 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] May 2021 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
May 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] May 2021 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Greynoiseio
Malicious Tag Roundup (January 2022)
blogs_greynoiseio
Malicious Tag Roundup (January 2022)
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
http://packetstormsecurity.com/files/162722/Microsoft-HTTP-Protocol-Stack-Remote-Code-Execution.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31166http://packetstormsecurity.com/files/162722/Microsoft-HTTP-Protocol-Stack-Remote-Code-Execution.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31166https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-31166
2021-05-11
Published
2022-04-06
Added to CISA KEV
Exploited in the wild