Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-33096

Опубликовано: 14 апр. 2026
Источник: msrc
CVSS3: 7.5
EPSS Низкий

Описание

HTTP.sys Denial of Service Vulnerability

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

Меры по смягчению последствий

Mitigation refers to a setting, common configuration, or general best-practice, existing in a default state, that could reduce the severity of exploitation of a vulnerability.

The following mitigating factors might help in your situation:

Caution Follow these steps carefully. Serious problems might occur if you modify the registry incorrectly.

To disable HTTP/3, remove the following registry values from the specified key:

  1. Open Registry Editor (regedit.exe).
  2. Navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTP\Parameters.
  3. Back up the key: select Parameters, then select File > Export, and save the .reg file to a secure location.
  4. If present, delete the EnableHttp3 value.
  5. If present, delete the EnableAltSvc value.
  6. Restart the device after making these changes.

After the restart, all http.sys-based server applications on that device will no longer serve HTTP/3 clients.

Note: If either value is not present, no change is required for that value.

Restore: To undo this change, double-click the exported .reg file (or in Registry Editor, select File > Import) to restore the previous settings.

After you install the security update, you no longer need this mitigation.

Обновления

ПродуктСтатьяОбновление
Windows Server 2022
Windows Server 2022 (Server Core installation)
Windows 11 Version 23H2 for ARM64-based Systems
Windows 11 Version 23H2 for x64-based Systems
Windows Server 2022, 23H2 Edition (Server Core installation)
Windows 11 Version 24H2 for ARM64-based Systems
Windows 11 Version 24H2 for x64-based Systems
Windows Server 2025
Windows Server 2025 (Server Core installation)
Windows 11 Version 25H2 for ARM64-based Systems

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 66%
0.01248
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
4 месяца назад

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
github
4 месяца назад

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость драйвера HTTP.sys операционных систем Windows, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 66%
0.01248
Низкий

7.5 High

CVSS3