CVE detail
CVE-2021-31166
HTTP Protocol Stack Remote Code Execution Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 23.0 · diversity 13.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
9 source links · newest first
- Security Affairs newsletter Round 316Security Affairs
A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. A malware attack hit the Alaska Health Department CVE-2021-31166 Windows HTTP flaw also impacts WinRM servers Zeppelin ransomware gang is back after a temporary pause 13 flaws in Nagios IT […]
newssecurityaffairs.comMay 30, 2021, 11:55 AM - CVE-2021-31166 Windows HTTP flaw also impacts WinRM serversSecurity Affairs
The wormable CVE-2021-31166 vulnerability in the HTTP Protocol Stack of the Windows IIS server also affects WinRM on Windows 10 and Server systems. Microsoft Patch Tuesday for May 2021 security updates addressed 55 vulnerabilities in Microsoft including a critical HTTP Protocol Stack Remote Code Execution vulnerability tracked as CVE-2021-31166. The flaw could be exploited by an unauthenticated […]
newssecurityaffairs.comMay 23, 2021, 1:25 PM - Security Affairs newsletter Round 315Security Affairs
A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. Avaddon Ransomware gang hacked France-based Acer Finance and AXA Asia MSBuild tool used to deliver RATs filelessly Pakistan-linked Transparent Tribe APT expands its arsenal Two flaws could allow bypassing AMD […]
newssecurityaffairs.comMay 23, 2021, 12:33 PM A researcher has released a proof-of-concept (PoC) exploit for a recently patched Windows vulnerability that could allow remote code execution and which has been described by Microsoft as wormable.
newswww.securityweek.comMay 18, 2021, 2:01 PM- 17th May – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 17th May, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Ireland’s Health Services Executive (HSE), a provider of health and social services, among them Covid-19 vaccines, has suffered an attack by Conti ransomware, forcing it to shut down its IT systems. Vaccine […]
vendorresearch.checkpoint.comMay 17, 2021, 6:11 PM - Expert released PoC exploit code for Windows CVE-2021-31166 bugSecurity Affairs
A security researcher has published a working proof-of-concept exploit code for a wormable Windows IIS server vulnerability tracked as CVE-2021-31166. Microsoft Patch Tuesday for May 2021 security updates addressed 55 vulnerabilities in Microsoft including a critical HTTP Protocol Stack Remote Code Execution vulnerability tracked as CVE-2021-31166. The flaw could be exploited by an unauthenticated attacker by […]
newssecurityaffairs.comMay 17, 2021, 1:45 PM - Microsoft Patch Tuesday for May 2021 fix 4 critical flawsSecurity Affairs
Microsoft Patch Tuesday for May 2021 security updates addressed 55 vulnerabilities, four are rated as Critical. Microsoft Patch Tuesday for May 2021 security updates address 55 vulnerabilities in Microsoft Windows, .NET Core and Visual Studio, Internet Explorer (IE), Microsoft Office, SharePoint Server, Open-Source Software, Hyper-V, Skype for Business and Microsoft Lync, and Exchange Server. Four […]
newssecurityaffairs.comMay 12, 2021, 9:39 PM - May 2021 Patch Tuesday: Adobe fixes exploited Reader 0-day, Microsoft patches 55 holesHelp Net Security
On this May 2021 Patch Tuesday: Adobe has fixed a Reader flaw exploited in attacks in the wild, as well as delivered security updates for eleven other products, including Magento, Adobe InDesign, Adobe After Effects, Adobe Creative Cloud Desktop Application, and others Microsoft has plugged 55 security holes, none actively exploited SAP has released 14 new and updated security patches Adobe updates Adobe has released security updates for 12 of its products, fixing a total of … More →
newswww.helpnetsecurity.comMay 12, 2021, 8:40 AM Microsoft’s monthly security patch release for May 2021 includes cover for 55 documented vulnerabilities, some serious enough to expose Windows users to remote code execution attacks.
newswww.securityweek.comMay 11, 2021, 6:45 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-40449CVSS 7.8 · High
Win32k Elevation of Privilege Vulnerability
- CVE-2021-34486CVSS 7.8 · High
Windows Event Tracing Elevation of Privilege Vulnerability
- CVE-2021-43226CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
KEV listed3 mentions - CVE-2021-41379CVSS 5.5 · Medium
Windows Installer Elevation of Privilege Vulnerability
- CVE-2021-41357CVSS 7.8 · High
Win32k Elevation of Privilege Vulnerability
KEV listed - CVE-2021-40450CVSS 7.8 · High
Win32k Elevation of Privilege Vulnerability
KEV listed