What a coincidence 🥲
____
CVE of the Week
CVE-2026-33096: High-Severity Remote DoS in Windows HTTP.sys
This out-of-bounds read flaw allows an unauthenticated, remote attacker to trigger a Denial of Service (DoS) condition by sending specially crafted network packets, causing targeted systems to crash or become unstable.
Why it matters:
- This flaw impacts the foundational networking component of Windows, affecting everything from web servers to internal networking roles.
- Attackers could crash systems remotely without any user action or authentication.
- A single exploit could take down critical services that rely on kernel-mode HTTP processing.
Recommended actions:
1. Immediately install the latest April Microsoft security cumulative updates to patch the http.sys driver.
2. If immediate patching is not an option, mitigate the risk by disabling HTTP/3 support via the registry (EnableHttp3 and EnableAltSvc values).
To implement the official Microsoft-recommended workaround, use this script from the Vicarius Research Team: https://www.vicarius.io/vsociety/posts/cve-2026-33096-mitigation-script-httpsys-denial-of-service-vulnerability
Let us know if you tried it in your environment and how the process went for you.
(Special thanks to @calif_io and the WARP & MORSE teams at Microsoft for their research 🤝)
Post summary
The post announces CVE-2026-33096, a high‑severity remote DoS flaw in Windows HTTP.sys, and urges users to apply Microsoft patches or use registry workarounds such as disabling HTTP/3.
CVE-2026-33096 Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. https://www.cve.org/CVERecord?id=CVE-2026-33096
Post summary
The post announces CVE-2026-33096, an out‑of‑bounds read in Windows HTTP.sys that can lead to a denial‑of‑service, with no mention of patches, PoC or active exploitation.