Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when the default AcceptFilter is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted requests.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jul 20, 2014 | Jul 20, 2014 |
| Freebsd | — | Upgrade apache24 | Dec 10, 2025 | Jul 19, 2014 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Jul 20, 2014 |
| Huawei Euleros 2_0_sp3 | — | Upgrade httpd-manualUpgrade httpd-toolsUpgrade httpdUpgrade httpd-develUpgrade mod_ssl | Sep 28, 2020 | Jul 20, 2014 |
| Suse | — | Upgrade apache2-develUpgrade apache2-docUpgrade apache2-utilsUpgrade apache2Upgrade apache2-preforkUpgrade apache2-workerUpgrade apache2-example-pages | Dec 9, 2016 | Jul 20, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub