PT-2022-4424 · Microsoft · Windows Http.Sys+1

Polar Bear

·

Published

2022-08-09

·

Updated

2023-06-07

·

CVE-2022-35748

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Windows HTTP.sys (affected versions not specified)
Description The issue is related to insufficient input validation in the HTTP.sys driver of the Windows operating system. It can be exploited by a remote attacker using a specially crafted request to cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-05288
CVE-2022-35748

Affected Products

Windows
Windows Http.Sys