Windows HTTP Protocol Stack
CVE-2022-21907 — HTTP Protocol Stack Remote Code Execution Vulnerability
Executive Summary
None
Overview
9.8
CVSS CRITICAL
Critical
MS Severity
Not Exploited
MS Exploit Status
More Likely
MS Exploit Likelihood
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 8.5
EPSS Score
0.9279
probability of exploitation in the next 30 days
0.9982 percentile - updated 2026-08-14
View on FIRST.org
Affected Products
18 affected products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 1809 for 32-bit Systems | 5009557 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 1809 for ARM64-based Systems | 5009557 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5009557 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 20H2 for 32-bit Systems | 5009543 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 20H2 for ARM64-based Systems | 5009543 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 21H1 for 32-bit Systems | 5009543 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 21H1 for ARM64-based Systems | 5009543 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 21H1 for x64-based Systems | 5009543 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5009543 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5009543 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5009543 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 11 version 21H2 for ARM64-based Systems | 5009566 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows 11 version 21H2 for x64-based Systems | 5009566 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2019 | 5009557 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2019 (Server Core installation) | 5009557 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2022 | 5009555 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2022 (Server Core installation) | 5009555 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server, version 20H2 (Server Core Installation) | 5009543 (Security Update) |
Critical | Remote Code Execution | Yes |
Patches
4 patches
| Article | Type | Restart |
|---|---|---|
5009557 |
Security Update | Yes |
5009543 |
Security Update | Yes |
5009566 |
Security Update | Yes |
5009555 |
Security Update | Yes |
Exploits & PoC
15 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| ZZ-SOCMAP/CVE-2022-21907 | 360 | 2022-01-17 | HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907 |
| polakow/CVE-2022-21907 | 128 | 2022-04-04 | A REAL DoS exploit for CVE-2022-21907 |
| p0dalirius/CVE-2022-21907-http.sys | 82 | 2022-01-17 | Proof of concept of CVE-2022-21907 Double Free in http.sys driver, triggering a kernel crash on IIS servers |
| michelep/CVE-2022-21907-Vulnerability-PoC | 28 | 2022-01-23 | CVE-2022-21907 Vulnerability PoC |
| mauricelambert/CVE-2022-21907 | 26 | 2022-01-15 | CVE-2022-21907: detection, protection, exploitation and demonstration. Exploitation: Powershell, Python, Ruby, NMAP and Metasploit. Detection and protection: Powershell. Demonstration: Youtube. |
| Malwareman007/CVE-2022-21907 | 17 | 2022-10-29 | POC for CVE-2022-21907: HTTP Protocol Stack Remote Code Execution Vulnerability. |
| 0xmaximus/Home-Demolisher | 8 | 2022-11-22 | PoC for CVE-2021-31166 and CVE-2022-21907 |
| corelight/cve-2022-21907 | 5 | 2022-01-11 | cve-2022-21907 |
| gpiechnik2/nmap-CVE-2022-21907 | 2 | 2022-04-16 | Repository containing nse script for vulnerability CVE-2022-21907. It is a component (IIS) vulnerability on Windows. It allows remote code execution. The vulnerability affects the kernel module http. |
| iveresk/cve-2022-21907-http.sys | 1 | 2022-05-10 | An unauthenticated attacker can send an HTTP request with an "Accept-Encoding" HTTP request header triggering a double free in the unknown coding-list inside the HTTP Protocol Stack (http.sys) to proc |
| iveresk/cve-2022-21907 | 1 | 2022-05-16 | Multithread Golang application |
| kamal-marouane/CVE-2022-21907 | 1 | 2023-12-09 | Vulnerability in HTTP Protocol Stack Enabling Remote Code Execution and Potential System Crash. |
| cassie0206/CVE-2022-21907 | 0 | 2023-04-25 | 2022 Spring Prof. 謝續平 |
| EzoomE/CVE-2022-21907-RCE | 0 | 2023-05-06 | CVE-2022-21907漏洞RCE PoC |
| asepsaepdin/CVE-2022-21907 | 0 | 2023-08-17 |
Detection Rules
No public Sigma or Nuclei detection rule has been mapped to this CVE yet. Coverage is concentrated on exploited / high-profile vulnerabilities; check SigmaHQ for updates.
Acknowledgments
References
On This Page