Bottom line: Successful exploitation of this vulnerability can result in a denial-of-service condition, leading to significant downtime and data loss.
What's happening: Yazhi Wang and Jonathan Lein of the TrendAI Research team discovered a remote code execution bug in the Windows HTTP protocol stack, which is used by the Windows operating system and many web servers. The vulnerability was patched by Microsoft in Patch Tuesday on February 7, 2023.
What to do: Security leaders should ensure that all systems running Windows HTTP.sys are updated to the latest patch, and consider implementing additional security controls to mitigate the risk of this vulnerability, such as implementing network segmentation and monitoring for suspicious activity.