Microsoft Windows HTTP.sys Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Windows HTTP.sys, allowing an unauthorized attacker to cause uncontrolled resource consumption over the network. This vulnerability affects multiple Windows 10 and Windows 11 versions, as well as Windows Server 2019, Windows Server 2022, and several other platforms.

Impact

Exploitation of this vulnerability leads to a significant denial-of-service condition, causing high resource consumption and potentially disrupting normal network operations.

Remediation

Security updates are available for all affected Windows versions. Instructions for downloading these updates can be found in the Microsoft Update Catalog.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.6
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.