Skip to main content

Microsoft Windows HTTP.sys Denial of Service Vulnerability

Last Update Date: 15 May 2013 14:24 Release Date: 15 May 2013 3381 Views

RISK: High Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

A denial of service vulnerability exists in Windows Server 2012 and Windows 8 when the HTTP protocol stack (HTTP.sys) improperly handles a malicious HTTP header. An attacker who successfully exploited this vulnerability could trigger an infinite loop in the HTTP protocol stack by sending a specially crafted HTTP header to an affected Windows server or client.


Impact

  • Denial of Service

System / Technologies affected

  • Windows 8
  • Windows Server 2012
  • Windows RT

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link