CVE-2023-35298
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2023-35298 is a Denial of Service (DoS) vulnerability affecting HTTP.sys, a component in Microsoft Windows operating systems. Maliciously crafted HTTP packets can trigger an infinite loop in HTTP.Sys, leading to a denial of service condition. This issue can be exploited through remote means, potentially allowing an attacker to cause significant network congestion or crashes. Microsoft has released a patch to address this vulnerability, and it is recommended that all affected systems be updated promptly. Failure to do so may result in prolonged disruptions to network availability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Windows 11 21H2
- Microsoft Windows 11 22h2
- Windows Server 2022
Affected Vendors
- Microsoft