In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, Kc Udonsi and Yazhi Wang of the Trend Micro Research Team detail a recent code execution vulnerability in the Microsoft Internet Information Services (IIS) for Windows. The bug was originally discovered by the Microsoft Platform Security & Vulnerability Research team. The following is a portion of their write-up covering CVE-2021-31166, with a few minimal modifications.
The Internet Information Services (IIS) for Windows Server is a flexible, scalable, secure, and manageable web server for hosting static as well as dynamic content on the :
Example "Accept-Encoding" headers are as above. It can either be unknown or supported. A supported content-coding string is a valid content-coding string specifying a compression algorithm supported by IIS.
In the following “Accept-Encoding” HTTP request header example:
Accept-Encoding: gzip, aaaa, bbbb;
“gzip” is a supported content-coding string, “aaaa” is an unknown content-coding string, and finally “bbbb;” is an invalid content-coding string because it is improperly formatted.
During the processing of the Field-Value string, the routine HTTP!UlpParseAcceptEncoding maintains a circular doubly this vulnerability in the May patch release cycle. They recommend prioritizing the patching of affected servers.
Special thanks to Kc Udonsi and Yazhi Wang of the Trend Micro Research Team for providing such a thorough analysis of this vulnerability. For an overview of Trend Micro Research services please visit for the latest in exploit techniques and security patches.
SOCIAL SHARE CARD GENERATOR