Microsoft HTTP.SYS Remote Denial of Service Vulnerability
Vulnerability Details
This vulnerability allows remote attackers to cause a denial of service condition on vulnerable installations of IIS. No user interaction is required to exploit this vulnerability.
The specific flaw exists within handling of HTTP headers in the Windows kernel. By providing a duplicate of a particular header, an attacker is able to cause an infinite loop in the HTTP header parser. This will fully exhaust the resources of one processor on the vulnerable server and will prevent IIS from responding to any other requests.
Additional Details
Microsoft has issued an update to correct this vulnerability. More details can be found at:
https://technet.microsoft.com/en-us/security/bulletin/ms13-039
Disclosure Timeline
- 2013-03-22 - Vulnerability reported to vendor
- 2013-05-29 - Coordinated public release of advisory
Credit
Marek Kroemeke
22733db72ab3ed94b5f8a1ffcde850251fe6f466
AKAT-1