Impact
A flaw in Windows HTTP.sys permits an attacker to create an unbounded allocation of system resources without any imposed limits or throttling. This allows the host to exhaust critical resources, leading to a denial of service condition where legitimate network requests cannot be served. The weakness is classified as CWE-770, which describes an unbounded resource allocation flaw.
Affected Systems
The vulnerability impacts Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 24H2, 25H2, and 26H1; and Windows Server 2016, 2019, 2022, and 2025—including Server Core installations. Any machine running HTTP.sys from these operating systems on any architecture (x86, x64, arm64) is susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates a medium‑high severity. less than 1% suggests that, at present, exploitation is not listed in CISA’s KEV catalog. The likely attack vector is remote, over a network: an adversary can craft specific HTTP requests to a vulnerable host, causing resource exhaustion. While the flaw does not grant code execution or privilege escalation, it can make the target unresponsive, impacting availability for critical services.
OpenCVE Enrichment