CVE-2023-35298

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jul 11, 2023
Updated: May 29, 2024
CWE ID 400

Summary

CVE-2023-35298 is a Denial of Service (DoS) vulnerability affecting HTTP.sys, a component in Microsoft Windows operating systems. Maliciously crafted HTTP packets can trigger an infinite loop in HTTP.Sys, leading to a denial of service condition. This issue can be exploited through remote means, potentially allowing an attacker to cause significant network congestion or crashes. Microsoft has released a patch to address this vulnerability, and it is recommended that all affected systems be updated promptly. Failure to do so may result in prolonged disruptions to network availability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Windows 11 21H2
  • Microsoft Windows 11 22h2
  • Windows Server 2022

Affected Vendors

  • Microsoft