Vulnerability Description
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 7 | - |
| Microsoft | Windows 8 | - |
| Microsoft | Windows 8.1 | - |
| Microsoft | Windows Server 2008 | r2 |
| Microsoft | Windows Server 2012 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/131463/Microsoft-Windows-HTTP.sys-Proof-Of-ExploitThird Party AdvisoryVDB Entry
- http://www.osvdb.org/120629Broken Link
- http://www.securityfocus.com/bid/74013Third Party AdvisoryVDB EntryBroken Link
- http://www.securitytracker.com/id/1032109Third Party AdvisoryVDB EntryBroken Link
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-03PatchVendor Advisory
- https://www.exploit-db.com/exploits/36773/ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/36776/ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/131463/Microsoft-Windows-HTTP.sys-Proof-Of-ExploitThird Party AdvisoryVDB Entry
- http://www.osvdb.org/120629Broken Link
- http://www.securityfocus.com/bid/74013Third Party AdvisoryVDB EntryBroken Link
- http://www.securitytracker.com/id/1032109Third Party AdvisoryVDB EntryBroken Link
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-03PatchVendor Advisory
- https://www.exploit-db.com/exploits/36773/ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/36776/ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-US Government Resource
FAQ
What is CVE-2015-1635?
CVE-2015-1635 is a vulnerability with a CVSS score of 9.8 (CRITICAL). HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests...
How severe is CVE-2015-1635?
CVE-2015-1635 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-1635?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows 7, Microsoft Windows 8, Microsoft Windows 8.1, Microsoft Windows Server 2008, Microsoft Windows Server 2012.