Vulnerability record · CVE-2013-1305 · published 15 May 2013
CVE-2013-1305: Microsoft Windows HTTP.sys crafted header denial of service
Microsoft · Windows 8
HTTP.sys in Windows 8, Windows Server 2012 and Windows RT enters an infinite loop when it processes a crafted HTTP header, causing a denial of service. The kernel-mode HTTP listener is reachable by any remote client that can send a request, so the flaw matters for availability of web-facing or internal HTTP services on the affected platforms.
Description
HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability."
AV:N/AC:L/Au:N/C:N/I:N/A:C
Automated analysis
high priorityUnauthenticated remote availability impact on core Windows HTTP handling with a very high EPSS percentile, though no KEV listing or confirmed public exploit in the record.
What it is
HTTP.sys in Windows 8, Windows Server 2012 and Windows RT enters an infinite loop when it processes a crafted HTTP header, causing a denial of service. The kernel-mode HTTP listener is reachable by any remote client that can send a request, so the flaw matters for availability of web-facing or internal HTTP services on the affected platforms.
Impact
An unauthenticated remote attacker can drive HTTP.sys into an infinite loop and exhaust the affected service or system, denying HTTP service to legitimate users. There is no confidentiality or integrity impact per the CVSS vector; the effect is availability loss.
Attack surface
Reached over the network by sending a crafted HTTP header to a service that uses HTTP.sys on the affected Windows versions. No authentication or user interaction is required per the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is 0.54665 (99th percentile), indicating a high modeled likelihood of exploitation activity. No public exploit code is confirmed by the supplied record.
What to do
- Apply Microsoft security bulletin MS13-039 for the affected Windows 8, Windows Server 2012 and Windows RT systems.
- Inventory internet-facing and internal services that rely on HTTP.sys and prioritize patching those first.
- Where patching is delayed, restrict network access to HTTP.sys-based services to trusted clients and rate-limit or filter malformed headers at the perimeter.
- Monitor vendor and US-CERT advisories for updated guidance on this issue.
Detection
- Watch for HTTP.sys or w3wp process hangs, high CPU spin, and service unresponsiveness on affected Windows versions.
- Alert on repeated malformed or unusual HTTP headers reaching HTTP.sys-based services, especially from a single source.
- Correlate spikes in HTTP 500/503 responses or connection timeouts with inbound request patterns to identify header-based DoS attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-1305 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-1305), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.