EXPOSURES › CVE-2021-31166
CVE-2021-31166
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft's http.sys HTTP protocol stack contained a remote code execution vulnerability that was actively exploited in the wild.
The http.sys component in Windows allowed attackers to execute arbitrary code remotely, leading to system compromise. DIB organizations must ensure all Windows systems are patched immediately, as this vulnerability was known and actively exploited before patching. Failure to patch exposes systems to remote code execution, violating CMMC/NIST 800-171 requirements for timely patch management and system integrity.
Shame score — A known, actively exploited remote code execution vulnerability in a core Windows component that was not patched before exploitation, demonstrating severe negligence and avoidable risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |