QID 91993

Date Published: 2023-03-15

QID 91993: Microsoft Windows HTTP Protocol Stack Remote Code Execution (RCE) Vulnerability Update for March 2023

Microsoft has released security patches to fix HTTP Protocol Stack Remote Code Execution Vulnerability.

QID Detection Logic (Authenticated):
Windows 11 Version 22H2
Windows 11 version 21H2
Windows Server 2022

The KB Articles and the patched versions associated with the update:
The patch version is 10.0.22621.1413 (http.sys) for KB5023706
The patch version is 10.0.22000.1696 (http.sys) for KB5023698
The patch version is 10.0.20348.1607 (http.sys) for KB5023705

Successful exploitation allows attacker to execute arbitrary code and compromise the system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Please refer to the following KB Articles associated with the update:
    KB5023706
    KB5023698
    KB5023705

    CVEs related to QID 91993

    Software Advisories
    Advisory ID Software Component Link
    KB5023698 URL Logo support.microsoft.com/help/5023698
    KB5023705 URL Logo support.microsoft.com/help/5023705
    KB5023706 URL Logo support.microsoft.com/help/5023706