Impact
The flaw stems from a partial string comparison defect in the Windows HTTP Protocol Stack, classified as CWE‑187. An unauthenticated attacker on an adjacent network can tamper with HTTP traffic, potentially modifying, injecting, or discarding data between client and server. Such tampering undermines the confidentiality and integrity of communications and can serve as a launch point for more advanced exploits such as request smuggling or denial of service.
Affected Systems
Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 on both standard and Core installations. The issue appears across 32‑bit and 64‑bit platforms as reflected in the associated CPE entries.
Risk and Exploitability
The CVSS score of 6.5 marks the vulnerability as medium severity, and the EPSS score of less than 1 % indicates a low likelihood of current exploitation. It is not listed in the CISA KEV catalog. An attacker must have local or adjacent network access and does not require privileged credentials. Despite the moderate score and low exploitation probability, the ability to alter traffic warrants timely remediation to prevent potential secondary attacks.
OpenCVE Enrichment