首页 Windows HTTP protocol stack remote code execution vulnerability (CVE-2021-31166)

Windows HTTP protocol stack remote code execution vulnerability (CVE-2021-31166)

更新时间: 2026-03-25 19:50:09

On May 11, 2021, Microsoft released a patch to address a critical remote code execution vulnerability in the Windows HTTP protocol stack. Microsoft has classified this vulnerability as wormable and likely to be exploited. Attackers can use this vulnerability to launch widespread worm attacks.

Vulnerability information

  • CVE ID: CVE-2021-31166

  • Vulnerability severity: Critical

  • Affected versions: Windows Server, version 2004 (Server Core installation)

    This includes the following operating system versions:

    • Windows Server Version 2004 Datacenter 64-bit (Chinese)

    • Windows Server Version 2004 Datacenter 64-bit (English)

    • Windows Server Version 2004 with Containers Datacenter 64-bit (Chinese)

    • Windows Server Version 2004 with Containers Datacenter 64-bit (English)

Description

This vulnerability affects the HTTP protocol stack (http.sys) in Windows 10 and Windows Server. This component is widely used for communication between applications and devices, and is used by common components such as Internet Information Services (IIS). An unauthenticated attacker can send a crafted malicious request to a target server. Successfully exploiting this vulnerability could allow an attacker to execute arbitrary code on the target server.

Security recommendations

Apply the official patch as soon as possible.

Solution

Download and apply the patch from the official Microsoft website. For more information, see CVE-2021-31166.

Announcing party

Alibaba Cloud Computing Co., Ltd.

阿里云首页 云服务器 ECS 相关技术圈