Body Background
TrendAI™ Zero Day Initiative™ Logo

Microsoft HTTP.SYS Remote Denial of Service Vulnerability

May 29th, 2013

Vulnerability Details


This vulnerability allows remote attackers to cause a denial of service condition on vulnerable installations of IIS. No user interaction is required to exploit this vulnerability.

The specific flaw exists within handling of HTTP headers in the Windows kernel. By providing a duplicate of a particular header, an attacker is able to cause an infinite loop in the HTTP header parser. This will fully exhaust the resources of one processor on the vulnerable server and will prevent IIS from responding to any other requests.

Additional Details

Microsoft has issued an update to correct this vulnerability. More details can be found at:
https://technet.microsoft.com/en-us/security/bulletin/ms13-039

Disclosure Timeline

  • 2013-03-22 - Vulnerability reported to vendor
  • 2013-05-29 - Coordinated public release of advisory

Credit

Marek Kroemeke
22733db72ab3ed94b5f8a1ffcde850251fe6f466
AKAT-1

Back to Advisories

Hero Background

Stand at the front line of proactive security

Trend ZDI connects the experts who discover, remediate, and defend.
Add your voice to the work that pushes attackers back.