Buffer overflow in Microsoft products - CVE-2022-21907
Published: January 11, 2022 / Updated: October 25, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the HTTP Trailer Support feature in HTTP Protocol Stack (http.sys). A remote attacker can send a specially crafted HTTP request to the web server, trigger a buffer overflow and execute arbitrary code on the system.
Affected software
Microsoft Windows
Windows Server
Solutions Enabler Virtual Appliance
Solutions Enabler
Unisphere 360
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
VASA Provider Standalone
How to mitigate CVE-2022-21907
Solutions Enabler - addressed in versions 9.1.0.19, 9.2.3.1
Unisphere 360 - addressed in versions 9.1.0.30, 9.2.3.4
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.1.0.32, 9.2.3.11
Unisphere for PowerMax - addressed in versions 9.1.0.32, 9.2.3.11
VASA Provider Standalone - addressed in versions 9.1.0.724, 9.2.3.10
Links to Public Exploits and PoC-codes
- Exploit #10648 - Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution (October 25, 2024)
- Exploit #8625 - Home-Demolisher (PoC for CVE-2021-31166 and CVE-2022-21907) (November 22, 2022)
- Exploit #8552 - CVE-2022-21907 (POC for CVE-2022-21907: HTTP Protocol Stack Remote Code Execution Vulnerability.) (October 31, 2022)
- Exploit #7878 - cve-2022-21907-http.sys (An unauthenticated attacker can send an HTTP request with an "Accept-Encoding" HTTP request header triggering a double free in the unknown coding-list inside the HTTP Protocol Stack (http.sys) to process packets, resulting in a ke (May 23, 2022)
- Exploit #7747 - cve-2022-21907 (Multithread Golang application) (May 11, 2022)
- Exploit #7664 - nmap-CVE-2022-21907 (Repository containing nse script for vulnerability CVE-2022-21907. It is a component (IIS) vulnerability on Windows. It allows remote code execution. The vulnerability affects the kernel module http. sys, which handles most basic IIS (April 18, 2022)
- Exploit #7661 - Microsoft HTTP Protocol Stack Denial Of Service (April 15, 2022)
- Exploit #7619 - CVE-2022-21907 (A REAL DoS exploit for CVE-2022-21907) (April 8, 2022)
- Exploit #7346 - CVE-2022-21907 (HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907) (February 13, 2022)
- Exploit #7295 - CVE_2022_21907-poc () (January 30, 2022)
- Exploit #7257 - CVE-2022-21907-Vulnerability-PoC (CVE-2022-21907 Vulnerability PoC) (January 25, 2022)
- Exploit #7256 - CVE_2022_21907-poc () (January 25, 2022)
- Exploit #7248 - CVE-2022-21907-http.sys (Proof of concept of CVE-2022-21907 Double Free in http.sys driver, triggering a kernel crash on IIS servers) (January 19, 2022)
- Exploit #7246 - CVE-2022-21907 (HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907) (January 17, 2022)