← Vulnerability feed

Vulnerability record · CVE-2021-31166 · published 11 May 2021

CVE-2021-31166: Microsoft Windows HTTP Protocol Stack use-after-free RCE

Microsoft · Windows 10 2004

The HTTP Protocol Stack in Microsoft Windows 10 2004/20H2 and Windows Server 2004/20H2 contains a use-after-free (CWE-416) that allows remote code execution. It is remotely reachable over the network with no authentication or user interaction, making it a serious wormable-style exposure for unpatched hosts.

9.8 CVSS 3.1 Critical CISA KEV since 6 Apr 2022 EPSS 100% · top 0.1% CWE-416 · Use after free
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

HTTP Protocol Stack Remote Code Execution Vulnerability

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, network-reachable with no authentication or interaction, use-after-free RCE, KEV-listed and near-maximum EPSS probability.

What it is

The HTTP Protocol Stack in Microsoft Windows 10 2004/20H2 and Windows Server 2004/20H2 contains a use-after-free (CWE-416) that allows remote code execution. It is remotely reachable over the network with no authentication or user interaction, making it a serious wormable-style exposure for unpatched hosts.

Impact

A remote, unauthenticated attacker can execute arbitrary code on the affected system, potentially gaining full control of the host.

Attack surface

Reached over the network via the HTTP protocol stack (AV:N, PR:N, UI:N); no authentication or user interaction is required.

Exploitation

Listed in CISA KEV since 2022-04-06 with a required action to apply vendor updates, and EPSS 30-day probability is 0.99772 (99.955th percentile), indicating very high likelihood of exploitation activity.

What to do

  • Apply the Microsoft security update referenced in the vendor advisory (portal.msrc.microsoft.com) to all affected Windows 10 2004/20H2 and Windows Server 2004/20H2 systems.
  • Prioritize internet-facing and HTTP-exposed Windows hosts for immediate patching.
  • Restrict or filter inbound HTTP traffic to affected systems where feasible until patched.
  • Verify patch deployment across all affected builds and reboot to complete installation.

Detection

  • Monitor for crashes or unexpected restarts of the HTTP Protocol Stack (http.sys) service on affected hosts.
  • Hunt for anomalous inbound HTTP requests or exploitation attempts against http.sys on unpatched Windows 10 2004/20H2 and Server 2004/20H2 systems.
  • Review host logs for suspicious process creation or code execution originating from the HTTP stack service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-31166 to the Known Exploited Vulnerabilities catalog on 6 April 2022 as "Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 27 April 2022.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-31166 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-21674Windows ALPC use-after-free privilege escalationCVE-2023-21674 is a use-after-free (CWE-416) in the Windows Advanced Local Procedure Call (ALPC) subsystem that allows elevation of privilege. It aff…KEVEPSS 41%analysed8.8CVE-2022-41128Windows Scripting Languages out-of-bounds write allows remote code executionCVE-2022-41128 is an out-of-bounds write (CWE-787) in Windows Scripting Languages that leads to remote code execution. Microsoft rates it 8.8 HIGH wi…KEVEPSS 25%analysed8.8CVE-2022-26923Microsoft Active Directory Domain Services certificate validation privilege escalationActive Directory Domain Services fails to properly validate certificate attributes, allowing a low-privileged domain user to obtain a certificate tha…KEVEPSS 84%analysed8.8CVE-2021-40444Microsoft MSHTML remote code execution via malicious Office documentCVE-2021-40444 is a remote code execution flaw in the MSHTML browser rendering engine on Microsoft Windows. An attacker can embed a malicious ActiveX…KEVEPSS 97%analysed8.8CVE-2021-34527Windows Print Spooler privileged file operation RCE (PrintNightmare)The Windows Print Spooler service improperly performs privileged file operations, allowing an attacker to execute arbitrary code as SYSTEM. This is t…KEVEPSS 100%analysed8.4CVE-2021-33739Microsoft DWM Core Library elevation of privilegeCVE-2021-33739 is an elevation of privilege flaw in the Microsoft Desktop Window Manager (DWM) Core Library affecting several Windows 10 and Windows …KEVEPSS 6.6%analysed7.8CVE-2023-28252Windows CLFS Driver Heap Buffer Overflow Elevation of PrivilegeThe Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow and out-of-bounds write. A local attacker who can run code on …KEVEPSS 49%analysed7.8CVE-2023-21823Windows Graphics Component integer overflow allows local code executionCVE-2023-21823 is an integer overflow (CWE-190) in the Microsoft Windows Graphics Component that can lead to remote code execution. It affects a broa…KEVEPSS 5.6%analysed

Source: NIST National Vulnerability Database (record CVE-2021-31166), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.