Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
CVE-2022-21907 — Microsoft Windows 10 Version 1809 vulnerability
11 documents10 sources
Severity
9.8CRITICALNVD
EPSS
91.9%
top 0.31%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 11
Latest updateJul 7
Description
HTTP Protocol Stack Remote Code Execution Vulnerability
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages10 packages
🔴Vulnerability Details
3💥Exploits & PoCs
1🔍Detection Rules
1Suricata▶
ET EXPLOIT Windows HTTP Protocol Stack UAF/RCE (CVE-2021-31166), http.sys DOS (CVE-2022-21907) Inbound↗2021-05-17