CVE-2021-31166 is a critical Remote Code Execution vulnerability affecting the HTTP Protocol Stack in various versions of Microsoft Windows 10 and Windows Server. With a CVSS score of 9.8, it presents a severe risk as it can be exploited remotely without authentication and has a high impact on confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as indicated by its presence in the KEV catalog, and has garnered significant community attention and media coverage, including a Metasploit module for denial-of-service. Its wormable nature and high FAUCET Risk Score of 100/100 underscore the urgency for patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.19041.982CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_2004:*:*:*:*:*:*:*:* | ||
< 10.0.19042.982CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_20h2:*:*:*:*:*:*:*:* | ||
< 10.0.19041.982CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2004:*:*:*:*:*:*:*:* | ||
< 10.0.19042.982CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_20h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.