Feed/CVE-2022-21907
CVE-2022-21907CRITICALCVSS 9.8

CVE-2022-21907

Published Jan 11, 2022·Updated Jun 16, 2026

NVD Description

HTTP Protocol Stack Remote Code Execution Vulnerability

Public Exploits & PoCs16 found

PoC: CVE-2022-21907

HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907

361

PoC: CVE-2022-21907

A REAL DoS exploit for CVE-2022-21907

113

PoC: CVE-2022-21907-http.sys

Proof of concept of CVE-2022-21907 Double Free in http.sys driver, triggering a kernel crash on IIS servers

65

PoC: CVE-2022-21907

CVE-2022-21907: detection, protection, exploitation and demonstration. Exploitation: Powershell, Python, Ruby, NMAP and Metasploit. Detection and protection: Powershell. Demonstration: Youtube.

20

PoC: CVE-2022-21907-Vulnerability-PoC

CVE-2022-21907 Vulnerability PoC

6

PoC: CVE-2022-21907-RCE-POC

CVE-2022-21907 Mass Exploitation tool written in Python 3 compatible with lists of URL/IPs. For a large number of targets you can increase the number of threads, we don't recommend more than 1024. This tool is NOT free to prevent abuse and do not expect to find a fix-it-all proof of concept for exploitation for free. Only for those knowledgeable.

4

PoC: cve-2022-21907

cve-2022-21907

4

PoC: CVE-2022-21907

POC for CVE-2022-21907: HTTP Protocol Stack Remote Code Execution Vulnerability.

2

PoC: CVE-2022-21907

HTTP Protocol Stack Remote Code Execution or System Crashing Vulnerability.

PoC: CVE-2022-21907-RCE

CVE-2022-21907漏洞RCE PoC

PoC: CVE-2022-21907

2022 Spring Prof. 謝續平

PoC: CVE-2022-21907

Poc exploit in CVE-2022-21907 . And testing the presence of cve

PoC: cve-2022-21907

Multithread Golang application

PoC: cve-2022-21907-http.sys

An unauthenticated attacker can send an HTTP request with an "Accept-Encoding" HTTP request header triggering a double free in the unknown coding-list inside the HTTP Protocol Stack (http.sys) to process packets, resulting in a kernel crash.

PoC: nmap-CVE-2022-21907

Repository containing nse script for vulnerability CVE-2022-21907. It is a component (IIS) vulnerability on Windows. It allows remote code execution. The vulnerability affects the kernel module http. sys, which handles most basic IIS operations.

PoC: CVE-2022-21907

CVE-2022-21907

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free