Vulnerability record · CVE-2021-31166 · published 11 May 2021
CVE-2021-31166: Microsoft Windows HTTP Protocol Stack use-after-free RCE
Microsoft · Windows 10 2004
The HTTP Protocol Stack in Microsoft Windows 10 2004/20H2 and Windows Server 2004/20H2 contains a use-after-free (CWE-416) that allows remote code execution. It is remotely reachable over the network with no authentication or user interaction, making it a serious wormable-style exposure for unpatched hosts.
Description
HTTP Protocol Stack Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, network-reachable with no authentication or interaction, use-after-free RCE, KEV-listed and near-maximum EPSS probability.
What it is
The HTTP Protocol Stack in Microsoft Windows 10 2004/20H2 and Windows Server 2004/20H2 contains a use-after-free (CWE-416) that allows remote code execution. It is remotely reachable over the network with no authentication or user interaction, making it a serious wormable-style exposure for unpatched hosts.
Impact
A remote, unauthenticated attacker can execute arbitrary code on the affected system, potentially gaining full control of the host.
Attack surface
Reached over the network via the HTTP protocol stack (AV:N, PR:N, UI:N); no authentication or user interaction is required.
Exploitation
Listed in CISA KEV since 2022-04-06 with a required action to apply vendor updates, and EPSS 30-day probability is 0.99772 (99.955th percentile), indicating very high likelihood of exploitation activity.
What to do
- Apply the Microsoft security update referenced in the vendor advisory (portal.msrc.microsoft.com) to all affected Windows 10 2004/20H2 and Windows Server 2004/20H2 systems.
- Prioritize internet-facing and HTTP-exposed Windows hosts for immediate patching.
- Restrict or filter inbound HTTP traffic to affected systems where feasible until patched.
- Verify patch deployment across all affected builds and reboot to complete installation.
Detection
- Monitor for crashes or unexpected restarts of the HTTP Protocol Stack (http.sys) service on affected hosts.
- Hunt for anomalous inbound HTTP requests or exploitation attempts against http.sys on unpatched Windows 10 2004/20H2 and Server 2004/20H2 systems.
- Review host logs for suspicious process creation or code execution originating from the HTTP stack service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-31166 to the Known Exploited Vulnerabilities catalog on 6 April 2022 as "Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 27 April 2022.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/162722/Microsoft-HTTP-Protocol-Stack-Remote-Code-Execution.html | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31166 | PatchVendor Advisory |
| http://packetstormsecurity.com/files/162722/Microsoft-HTTP-Protocol-Stack-Remote-Code-Execution.html | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-31166 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-31166 | US Government Resource |
Track CVE-2021-31166 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-31166), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.