QID 91852

Date Published: 2022-01-12

QID 91852: Microsoft Hypertext Transfer Protocol (HTTP) Protocol Stack Remote Code Execution (RCE) Vulnerability for January 2022

Microsoft Windows Security Update - January 2022 The KB Articles associated with the update:
KB5009557
KB5009566
KB5009543
KB5009555

This QID checks for the file version of http.sys

The following versions of http.sys with their corresponding KBs are verified:
KB5009557 - 10.0.17763.2452
KB5009543 - 10.0.19041.1466
KB5009566 - 10.0.22000.434
KB5009555 - 10.0.20348.469
Detection also checks for registry key "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTTP\Parameters" value "EnableTrailerSupport"=dword:00000001 on Windows 10 Version 1809 and Windows Server 2019 Operating Systems.

Successful exploit could compromise Confidentiality, Integrity and Availability

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Please refer to the KB5009557
    KB5009566
    KB5009543
    KB5009555

    CVEs related to QID 91852

    Software Advisories
    Advisory ID Software Component Link
    KB5009543 URL Logo support.microsoft.com/en-in/help/5009543
    KB5009555 URL Logo support.microsoft.com/en-in/help/5009555
    KB5009557 URL Logo support.microsoft.com/en-in/help/5009557
    KB5009566 URL Logo support.microsoft.com/en-in/help/5009566