A security vulnerability exists in the Windows HTTP protocol stack (HTTP.sys). A remote attacker can trigger a buffer overflow by sending a specific request to the server, thereby executing arbitrary code on the target system or causing a denial of service on the server. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021. Other reference:None