Security
Headlines
HeadlinesLatestCVEs

Tag

#HTTP.sys

CVE-2022-35838: HTTP V3 Denial of Service Vulnerability

Mitigation refers to a setting, common configuration, or general best-practice, existing in a default state, that could reduce the severity of exploitation of a vulnerability. The following mitigating factors might be helpful in your situation: A prerequisite for a server to be vulnerable is that the binding has HTTP/3 enabled and the server uses buffered I/O. HTTP/3 support for services is a new feature of Windows Server 2022. Currently, enabling HTTP/3 is done via a registry key as dicussed in this article: Enabling HTTP/3 support on Windows Server 2022

Microsoft Security Response Center
#vulnerability#web#windows#dos#HTTP.sys#Security Vulnerability