QID 91767
Date Published: 2021-05-12
QID 91767: Microsoft Windows HTTP Protocol Stack Remote Code Execution Vulnerability - May 2021
Microsoft Windows HTTP Protocol Stack is prone to Remote Code Execution Vulnerability.
Affected Operating Systems:
Windows Server, version 20H2 (Server Core Installation)
Windows 10 Version 20H2 for ARM64-based Systems
Windows 10 Version 20H2 for 32-bit Systems
Windows 10 Version 20H2 for x64-based Systems
Windows Server, version 2004 (Server Core installation)
Windows 10 Version 2004 for x64-based Systems
Windows 10 Version 2004 for ARM64-based Systems
Windows 10 Version 2004 for 32-bit Systems
QID Detection Logic (authenticated):
The QID checks for the version of file http.sys.
In most situations, an unauthenticated attacker can send a specially crafted packet to a targeted server utilizing the HTTP Protocol Stack (http.sys) to process packets leading to remote code execution.
- KB5003173 -
support.microsoft.com/help/5003173
CVEs related to QID 91767
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| KB5003173 |
|