CVE-2015-1635

microsoft windows 7, microsoft windows 8, microsoft windows 8.1

Published 14 Apr 2015 · updated 17 Jun 2026 · Analyzed

9.8 Critical · CVSS 3.1, CISA ADP

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 10 Feb 2022, with a remediation deadline of 10 Aug 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."

References