CVE-2014-3523 is a memory leak vulnerability affecting Apache HTTP Server 2.4.x before 2.4.10 on Windows, specifically within the WinNT MPM when the default AcceptFilter is enabled. This flaw allows remote attackers to trigger excessive memory consumption, leading to a denial of service. The vulnerability has a CVSS score of 5.0, indicating a medium severity, and is easily exploitable over the network with low attack complexity, resulting in a partial impact on availability. There is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. Despite its age, it has garnered some community discussion and media coverage, though the linked article is not directly related to this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.1CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.1:*:*:*:*:*:*:* | ||
2.4.2CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.2:*:*:*:*:*:*:* | ||
2.4.3CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.3:*:*:*:*:*:*:* | ||
2.4.4CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.4:*:*:*:*:*:*:* | ||
2.4.6CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.6:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: WinNT MPM denial of service
Jul 15, 2014Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project