Lucene search

K
cvelistMicrosoftCVELIST:CVE-2018-0956
HistoryApr 12, 2018 - 1:00 a.m.

CVE-2018-0956

2018-04-1201:00:00
microsoft
www.cve.org
6

AI Score

6.5

Confidence

High

EPSS

0.003

Percentile

69.9%

A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP 2.0 requests, aka “HTTP.sys Denial of Service Vulnerability.” This affects Windows Server 2016, Windows 10, Windows 10 Servers.

CNA Affected

[
  {
    "product": "Windows Server 2016",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "(Server Core installation)"
      }
    ]
  },
  {
    "product": "Windows 10",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "32-bit Systems"
      },
      {
        "status": "affected",
        "version": "Version 1511 for 32-bit Systems"
      },
      {
        "status": "affected",
        "version": "Version 1511 for x64-based Systems"
      },
      {
        "status": "affected",
        "version": "Version 1607 for 32-bit Systems"
      },
      {
        "status": "affected",
        "version": "Version 1607 for x64-based Systems"
      },
      {
        "status": "affected",
        "version": "Version 1703 for 32-bit Systems"
      },
      {
        "status": "affected",
        "version": "Version 1703 for x64-based Systems"
      },
      {
        "status": "affected",
        "version": "Version 1709 for 32-bit Systems"
      },
      {
        "status": "affected",
        "version": "Version 1709 for x64-based Systems"
      },
      {
        "status": "affected",
        "version": "x64-based Systems"
      }
    ]
  },
  {
    "product": "Windows 10 Servers",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "version 1709  (Server Core Installation)"
      }
    ]
  }
]

AI Score

6.5

Confidence

High

EPSS

0.003

Percentile

69.9%