CVE-2022-35748
published 2023-05-31CVE-2022-35748: HTTP.sys Denial of Service Vulnerability HTTP.sys Denial of Service Vulnerability
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
47.23%
98.7th percentile
HTTP.sys Denial of Service Vulnerability
HTTP.sys Denial of Service Vulnerability
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23817 | 6.2.9200.23817 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20520 | 6.3.9600.20520 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5291 | 10.0.14393.5291 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.3287 | 10.0.17763.3287 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.887 | 10.0.20348.887 |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < 10.0.19042.1889 | 10.0.19042.1889 |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_2022 | — | — |
| msrc | windows_server_version_20h2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →An unauthenticated attacker sends a specially crafted packet targeting the Server Name Indication (SNI) field over HTTP Protocol Stack (http.sys); monitor for anomalous or malformed SNI values in TLS/HTTPS traffic directed at Windows IIS servers running http.sys. ↗
- ·Exploitation is rated 'More Likely' for both latest and older software releases per Microsoft's assessment, meaning defenders should prioritize patching http.sys on all supported Windows versions. ↗
- ·The vulnerability affects Windows Internet Information Services via the HTTP Protocol Stack (http.sys); any Windows server exposing http.sys to untrusted network traffic is in scope. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cvelistv57.5HIGH
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
HTTP.sys Denial of Service Vulnerability
vendor_msrc·2022-08-09·CVSS 7.5
CVE-2022-35748 [HIGH] HTTP.sys Denial of Service Vulnerability
HTTP.sys Denial of Service Vulnerability
FAQ: How could an attacker exploit this vulnerability?
In most situations, an unauthenticated attacker could send a specially crafted packet to a targeted server utilizing the Server Name Indication (SNI) over HTTP Protocol Stack (http.sys) to process packets, causing a denial of service (DOS).
Windows Internet Information Services: Windows Internet Information Services
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5016623
Reference: https://support.microsoft.com/help/5016623
Reference:
CVEList
HTTP.sys Denial of Service Vulnerability
cvelistv5·2023-05-31·CVSS 7.5
CVE-2022-35748 [HIGH] HTTP.sys Denial of Service Vulnerability
HTTP.sys Denial of Service Vulnerability
HTTP.sys Denial of Service Vulnerability
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday for August 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-08-09·CVSS 8.0
[HIGH] Microsoft Patch Tuesday for August 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing more than 120 vulnerabilities across its line of products and software, the most in a single Patch Tuesday in four months.
This batch of updates also includes a fix for a new vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT) that’s actively being exploited in the wild, according to Microsoft. MSDT was already the target of the so-called “Follina” zero-day vulnerability in June.
In all, August’s Patch Tuesday includes 15 critical vulnerabilities and a single low- and moderate-severity issue. The remainder is classified as “important.”
Two of the important vulnerabilities CVE-2022-35743 and CVE-2022-34713 are remote code execution vulnerabilities in MSDT. However, only CVE-2022-34713 has been exploited
Talos
Microsoft Patch Tuesday for August 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-08-09·CVSS 8.0
[HIGH] Microsoft Patch Tuesday for August 2022 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for August 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing more than 120 vulnerabilities across its line of products and software, the most in a single Patch Tuesday in four months .
This batch of updates also includes a fix for a new vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT) that’s actively being exploited in the wild, according to Microsoft. MSDT was already the target of the so-called “Follina” zero-day vulnerability in June.
In all, August’s Patch Tuesday includes 15 critical vulnerabilities and a single low- and moderate-severity issue. The remainder is classified as “important.”
Two of the important vulnerabilities CVE-2022-35743 and CVE-2022-34713 are remote
2023-05-31
Published