CVE-2013-1305: Microsoft Windows 8

High severity, CVSS 7.8. EPSS: 54.7% chance of exploitation in the next 30 days.

HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability."

Affected products

  • Microsoft Windows 8: affected versions not specified
  • Microsoft Windows Rt: affected versions not specified
  • Microsoft Windows Server 2012: affected versions not specified

Published 2013-05-15. Last modified 2026-06-16.