CVE-2022-21907 is a critical vulnerability in the Windows HTTP Protocol Stack implemented by the kernel-mode driver http.sys. The flaw affects HTTP request processing on supported Windows client and server platforms, including systems commonly exposed through IIS or other services relying on http.sys. Analysis of the vulnerable code indicates improper initialization of an internal Tracker structure in the fast-response handling path, including MDL-related fields that are later referenced during cleanup. In the vulnerable path, malformed HTTP requests can trigger an alternate allocation and error-handling sequence in functions including UlpAllocateFastTracker() and UlFastSendHttpResponse(), causing cleanup logic to reach MmUnmapLockedPages() with invalid or uninitialized state. This can reliably crash the operating system. Remote code execution has been assessed as theoretically possible because attacker-influenced kernel memory state may be reachable, but public technical analysis primarily demonstrated denial of service rather than straightforward code execution. Exploitation is associated with HTTP Trailer Support being enabled, which is enabled by default on some affected systems.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
Single-file Python proof-of-concept exploit for CVE-2022-21907 targeting Microsoft HTTP.sys, commonly exposed via IIS. The repository contains one executable script, main.py, which accepts a target URL/host, normalizes it to HTTP if no scheme is provided, starts a monitoring thread that repeatedly performs GET requests to check reachability, then sends a crafted GET request with a malformed Accept-Encoding header designed to trigger a denial-of-service crash. The script does not provide code execution or shell access; its capability is limited to remote service disruption/crash verification. No hardcoded external infrastructure, IPs, domains, or file/registry artifacts are present beyond the user-supplied target URL.
This repository provides a proof-of-concept (PoC) exploit for CVE-2022-21907, a double free vulnerability in the http.sys driver on certain Microsoft Windows systems. The main exploit script, 'CVE-2022-21907_http.sys_crash.py', is a Python script that sends a specially crafted HTTP GET request with a malformed 'Accept-Encoding' header to a target IIS server. If the target is vulnerable, this triggers a double free in the http.sys kernel driver, resulting in a kernel crash (BSOD) and denial of service. The exploit is unauthenticated and works remotely over the network. The README provides detailed information about affected systems, required registry configuration, and includes references and a demonstration video. The repository also contains a crash trace file ('ressources/trace.txt') with kernel debugging output confirming the nature of the crash. No weaponized or post-exploitation payload is included; the exploit is focused solely on causing a denial of service.
This repository provides a comprehensive set of tools and scripts to exploit CVE-2022-21907, a critical vulnerability in Microsoft Windows HTTP Protocol Stack (http.sys) affecting IIS web servers. The vulnerability allows remote attackers to cause a denial of service (Blue Screen of Death) by sending a specially crafted HTTP request with a malformed 'Accept-Encoding' header. The repository includes exploit scripts in Python, Ruby, and PowerShell, as well as Metasploit and Nmap NSE modules for automated exploitation and detection. Additionally, PowerShell scripts are provided for detection and mitigation by checking and modifying the 'EnableTrailerSupport' registry value. The exploit targets unpatched Windows systems running IIS with the vulnerable configuration. The main attack vector is network-based, requiring only HTTP access to the target server. The repository is well-structured, with clear separation between detection, exploitation, and mitigation scripts, and includes detailed documentation and usage examples.
This repository contains a Python proof-of-concept exploit for CVE-2022-21907, a critical vulnerability in the HTTP Protocol Stack (http.sys) on various versions of Microsoft Windows and Windows Server. The exploit, implemented in 'cve-2022-21907.py', targets IIS servers by sending a large number of specially crafted HTTP or HTTPS requests with chunked transfer encoding and the 'TE: trailers' header. This can trigger a denial of service (DoS) condition on unpatched and vulnerable systems. The script supports both IPv4 and IPv6, and allows the user to specify the target IP, port, and IP version. The README provides detailed information on affected Windows versions, usage instructions, and mitigation steps, including the relevant registry key ('EnableTrailerSupport') that controls vulnerability on some systems. The repository is structured with a single exploit script, a README, and a license file. No fake or destructive code is present; the exploit is a legitimate DoS PoC for research and testing purposes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity vulnerability in Windows HTTP Protocol Stack/http.sys associated with IIS. The content describes it as a remote code execution vulnerability, though the demonstrated impact in the analysis is denial of service via system crash triggered by malformed HTTP packets; RCE is discussed as possible but unproven.
Kriittinen Windows HTTP.sys -komponentin haavoittuvuus, joka liittyy HTTP Trailer Support / "Trailer"-ominaisuuteen ja voi mahdollistaa etähyväksikäytön sekä matomaisen leviämisen organisaatiossa.
A remote code execution vulnerability in Microsoft's HTTP Protocol Stack (http.sys).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.