CVE-2015-1635
microsoft windows 7, microsoft windows 8, microsoft windows 8.1
Published 14 Apr 2015 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, CISA ADP
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 10 Feb 2022, with a remediation deadline of 10 Aug 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."
References
- packetstormsecurity.com/files/131463/Microsoft-Windows-HTTP.sys-Proof-Of-Concept.html · Exploit, Third Party Advisory, VDB Entry
- www.osvdb.org/120629 · Broken Link
- www.securityfocus.com/bid/74013 · Broken Link, Third Party Advisory, VDB Entry
- www.securitytracker.com/id/1032109 · Broken Link, Third Party Advisory, VDB Entry
- docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-034 · Patch, Vendor Advisory
- www.exploit-db.com/exploits/36773/ · Exploit, Third Party Advisory, VDB Entry
- www.exploit-db.com/exploits/36776/ · Exploit, Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-1635 · US Government Resource