Rapid7 Vulnerability & Exploit Database

Microsoft CVE-2019-9512: HTTP/2 Server Denial of Service Vulnerability

Back to Search

Microsoft CVE-2019-9512: HTTP/2 Server Denial of Service Vulnerability

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
08/13/2019
Created
08/14/2019
Added
08/13/2019
Modified
11/18/2021

Description

A denial of service vulnerability exists in the HTTP/2 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP/2 requests. An attacker who successfully exploited the vulnerability could create a denial of service condition, causing the target system to become unresponsive. To exploit this vulnerability, an unauthenticated attacker could send a specially crafted HTTP packet to a target system, causing the affected system to become nonresponsive. The update addresses the vulnerability by modifying how the Windows HTTP protocol stack handles HTTP/2 requests. Note that the denial of service vulnerability would not allow an attacker to execute code or to elevate user rights.

Solution(s)

  • msft-kb4511553-8eb289e2-ef30-46de-a545-1600b9255165
  • msft-kb4511553-9cdd3e34-499b-4c72-9be8-74f6946a1830
  • msft-kb4511553-c33e7db5-e128-4ca0-aa51-fcd3fd32bcb2
  • msft-kb4512497-6dbe32fb-5832-4dac-8ec8-31c4b0651e31
  • msft-kb4512497-d8fdba67-9336-4531-bc67-4d7eedc79b4f
  • msft-kb4512501-5570183b-a0b7-4478-b0af-47a6e65417ca
  • msft-kb4512501-d45c0b6d-99f1-4b6e-b7a0-2fbaa7335985
  • msft-kb4512501-e1c03faa-adc1-4068-97c4-089a33cb5add
  • msft-kb4512507-84eb119c-d9c4-487f-b45a-0b8188a2d270
  • msft-kb4512507-a50734e7-f388-46dd-b697-513537829ae3
  • msft-kb4512508-2b24eae0-5ba4-438f-bdae-7ed8347e2718
  • msft-kb4512508-35cff443-e9f5-4d0a-a8fc-7fe8a39ab515
  • msft-kb4512508-d4a24678-720e-4e4b-87d6-aa3ae8fceebc
  • msft-kb4512516-5909e402-b1ec-4dc4-8648-d73a81a115aa
  • msft-kb4512516-646eec92-7205-48d6-9a66-ba080e2824ed
  • msft-kb4512517-081388ab-f979-4aef-93fe-813c0044c838
  • msft-kb4512517-4a96dbb7-bbf9-4813-9bfe-b84b252fcaa7
  • msft-kb4512517-af89cf2e-ce74-4a9e-b16d-070888bce28c

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;