All Products
Search
Document Center

:Windows HTTP protocol stack remote code execution vulnerability (CVE-2021-31166)

Last Updated:Aug 25, 2026

On May 11, 2021, Microsoft released a patch to address a critical remote code execution vulnerability in the Windows HTTP protocol stack. Microsoft has classified this vulnerability as wormable and likely to be exploited. Attackers can use this vulnerability to launch widespread worm attacks.

Vulnerability information

  • CVE ID: CVE-2021-31166

  • Vulnerability severity: Critical

  • Affected versions: Windows Server, version 2004 (Server Core installation)

    This includes the following operating system versions:

    • Windows Server Version 2004 Datacenter 64-bit (Chinese)

    • Windows Server Version 2004 Datacenter 64-bit (English)

    • Windows Server Version 2004 with Containers Datacenter 64-bit (Chinese)

    • Windows Server Version 2004 with Containers Datacenter 64-bit (English)

Description

This vulnerability affects the HTTP protocol stack (http.sys) in Windows 10 and Windows Server. This component is widely used for communication between applications and devices, and is used by common components such as Internet Information Services (IIS). An unauthenticated attacker can send a crafted malicious request to a target server. Successfully exploiting this vulnerability could allow an attacker to execute arbitrary code on the target server.

Security recommendations

Apply the official patch as soon as possible.

Solution

Download and apply the patch from the official Microsoft website. For more information, see CVE-2021-31166.

Announced by

Alibaba Cloud Computing Co., Ltd.