Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability

Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.

Published 9 Sep 2026Updated 9 Sep 202672 sources
CVSS 9.8 PoC CANDIDATE△ CISA KEV

What happened

Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.

Affected versions

HTTP Protocol Stack: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
SploitusExploit for CVE-2021-31166. CVSS 9.8.Sploitus index2026-09-12T15:07:06+00:00Candidatekitploit.comDoS in IIS Web Server via malformed Accept-Encoding header with double commas causing BSOD.en2026-09-09T17:29:32CandidatePoC-in-GitHub · 0vercl0k/CVE-2021-31166Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.★ 8260vercl0k2021-05-16CandidatePoC-in-GitHub · zha0gongz1/CVE-2021-31166PoC for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely. Although it was defined as remote command execution, it can only cause the system to crash.★ 8zha0gongz12021-05-17CandidatePoC-in-GitHub · mvlnetdev/CVE-2021-31166-detection-rulesDifferent rules to detect if CVE-2021-31166 is being exploited★ 3mvlnetdev2021-05-17CandidatePoC-in-GitHub · corelight/CVE-2021-31166HTTP Protocol Stack CVE-2021-31166★ 12corelight2021-05-17CandidatePoC-in-GitHub · zecopro/CVE-2021-31166simple bash script for exploit CVE-2021-31166★ 5zecopro2021-05-19CandidatePoC-in-GitHub · bgsilvait/WIn-CVE-2021-31166★ 0bgsilvait2021-05-23CandidatePoC-in-GitHub · y0g3sh-99/CVE-2021-31166-ExploitExploit for MS Http Protocol Stack RCE vulnerability (CVE-2021-31166)★ 7y0g3sh-992021-07-03CandidatePoC-in-GitHub · ZZ-SOCMAP/CVE-2021-31166Windows HTTP协议栈远程代码执行漏洞 CVE-2021-31166★ 19ZZ-SOCMAP2021-09-27CandidatePoC-in-GitHub · iranzai/CVE-2021-31166-exploitJust a simple CVE-2021-31166 exploit tool★ 2iranzai2021-10-20CandidatePoC-in-GitHub · mauricelambert/CVE-2021-31166CVE-2021-31166: exploitation with Powershell, Python, Ruby, NMAP and Metasploit.★ 6mauricelambert2022-03-07CandidatePoC-in-GitHub · 0xmaximus/Home-DemolisherPoC for CVE-2021-31166 and CVE-2022-21907★ 80xmaximus2022-11-22Candidate