CVE-2021-31166

CRITICAL KEV RANSOMWARE LAB

Windows IIS HTTP Protocol Stack DOS

Title source: metasploit

Description

HTTP Protocol Stack Remote Code Execution Vulnerability

Exploits (20)

nomisec WORKING POC 829 stars
by 0vercl0k · dos
https://github.com/0vercl0k/CVE-2021-31166
nomisec WORKING POC 19 stars
by ZZ-SOCMAP · poc
https://github.com/ZZ-SOCMAP/CVE-2021-31166
nomisec SCANNER 13 stars
by corelight · poc
https://github.com/corelight/CVE-2021-31166
nomisec WORKING POC 8 stars
by zha0gongz1 · dos
https://github.com/zha0gongz1/CVE-2021-31166
nomisec SCANNER 7 stars
by 0xmaximus · dos
https://github.com/0xmaximus/Home-Demolisher
nomisec WORKING POC 7 stars
by y0g3sh-99 · dos
https://github.com/y0g3sh-99/CVE-2021-31166-Exploit
github WORKING POC 6 stars
by Y5neKO · pythonpoc
https://github.com/Y5neKO/ExpAndPoc_Collection/tree/main/CVE-2021-31166
nomisec WORKING POC 5 stars
by zecopro · dos
https://github.com/zecopro/CVE-2021-31166
nomisec SCANNER 3 stars
by mvlnetdev · poc
https://github.com/mvlnetdev/CVE-2021-31166-detection-rules
nomisec SUSPICIOUS 2 stars
by iranzai · poc
https://github.com/iranzai/CVE-2021-31166-exploit
gitlab WORKING POC
by securitystuffbackup · poc
https://gitlab.com/securitystuffbackup/CVE-2021-31166
gitlab WORKING POC
by securitystuffbackup · poc
https://gitlab.com/securitystuffbackup/CVE-2021-31166-2
nomisec WORKING POC
by bgsilvait · poc
https://github.com/bgsilvait/WIn-CVE-2021-31166
metasploit WORKING POC
by Max, Stefan Blair, Axel Souchet · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/windows/http/http_sys_accept_encoding_dos_cve_2021_31166.rb
patchapalooza WORKING POC
by liang2kl · dos
https://github.com/liang2kl/iot-exploits
patchapalooza WORKING POC
by mauricelambert · dos
https://github.com/mauricelambert/CVE-2021-31166
patchapalooza WORKING POC
by ckz-code · poc
https://gitee.com/ckz-code/CVE-2021-31166
patchapalooza WORKING POC
by mirrors_trending · poc
https://gitee.com/mirrors_trending/CVE-2021-31166
patchapalooza WORKING POC
by ljygit123 · poc
https://gitee.com/ljygit123/CVE-2021-31166

Scores

CVSS v3 9.8
EPSS 0.9307
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Lab Environment

COMMUNITY
Community Lab
docker pull vulhub/struts2:2.5.25
docker pull liang2kl/fat-docker
docker pull liang2kl/fap-docker:2.3.1
docker pull vulhub/rocketmq:5.1.0
+11 more repos

Details

CISA KEV 2022-04-06
VulnCheck KEV 2022-03-24
InTheWild.io 2022-04-06
ENISA EUVD EUVD-2021-18079
Ransomware Use Confirmed
CWE
CWE-416
Status published
Products (4)
microsoft/windows_10_2004 < 10.0.19041.982
microsoft/windows_10_20h2 < 10.0.19042.982
microsoft/windows_server_2004 < 10.0.19041.982
microsoft/windows_server_20h2 < 10.0.19042.982
Published May 11, 2021
KEV Added Apr 06, 2022
Tracked Since Feb 18, 2026