Exploit code released puts Windows 10 20H2 and Windows Server 20H2 at risk
Vulnerability CVE-2021-3166 was first discovered in the HTTP Protocol Stack (HTTP.sys) used by the Windows Internet Information Services (IIS) web server as the protocol handler for handling HTTP requests.
However, to exploit this vulnerability, an attacker would have to send a special packet to servers that still use the vulnerable HTTP Protocol Stack to process the packets. Thankfully, however, Microsoft recently patched this vulnerability as part of its recent Patch Tuesday update, so the vulnerability only affects Windows 10 20H2 and Windows Server 20H2.
Because this bug could allow an unauthenticated attacker to remotely execute arbitrary code, Microsoft recommends that organizations patch all affected servers as soon as possible.
Security researcher Alex Souchet has released a PoC that lacks auto-spreading to show how an attacker can leverage CVE-2021-3166 to carry out attacks on Windows 10 systems and servers. vulnerable to attack.
By abusing the use-after-free vulnerability in HTTP.sys, Souchet's exploit could trigger a denial of service (DoS) attack leading to a blue screen of death (BSoD) on vulnerable systems. public.
While releasing a PoC exploit for this vulnerability may make it easier for cybercriminals to develop their own exploits, the fact is that the vulnerability was patched and released by Microsoft during the Windows Update. 10, which means most systems are safe from attacks.
However, if you haven't installed the latest Windows 10 update from Microsoft, now is the time to do so to avoid falling victim to any potential attacks that take advantage of this vulnerability.
You should read it
- Windows 10 KB5001330: Prevent these serious problems in the latest update
- Microsoft reminds users that Windows Server 20H2 is about to be discontinued
- Windows 10 20H2: The first information is revealed
- Top 10 cool features on Windows 10 20H2
- Microsoft confirms Windows 10 20H2 has a blue screen error and restarts by itself
- How to download and create a Windows 10 October 2020 Update 20H2 installer by USB
- Microsoft issues an urgent warning to users of Windows 10 versions 1909 and 20H2
- Microsoft released the Windows 10 Iron 21H1 update on the Windows Insider Program
- 4 How to Update Windows 10 October 2020 Update
- Microsoft releases update KB4580364, which resolves crashes on Windows 10
- How to fix Windows 10 failure to update error KB5003173
- Microsoft Defender is causing a series of problems with Windows 10 version 20H2
Maybe you are interested
There is a serious security vulnerability that has existed for 18 years in AMD processors, but it is not too worrying
A dangerous vulnerability that has existed for 18 years threatens millions of AMD Ryzen and EPYC CPUs
Google Workspace security vulnerability caused thousands of user accounts to be attacked
Thousands of iOS apps could be at risk because of an open source vulnerability
Serious vulnerability in OpenSSH threatens millions of servers
Google releases emergency update to patch Chrome vulnerability