CVE-2015-1635
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."
- Affected products
- Windows, Windows 7, Windows 8, Windows 8.1, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2
- Microsoft Windows 7
- All versions
- Microsoft Windows 8
- All versions
- Microsoft Windows 8.1
- All versions
- Microsoft Windows Server 2008
- = R2
- Microsoft Windows Server 2012
- All versions
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 100.0% (100th percentile)
- Weakness
- CWE-94
- NVD status
- Analyzed
- Published
- 2015-04-14
CVE-2015-1635 at NVD
29 known exploits for CVE-2015-1635
Proof-of-concept code and exploit modules indexed by Sploitus
Project-CVE-2015-1635
CVE-2015-1635-POC
erlvulnscan
CVE-2015-1635-POC
Remove-IIS-RIIS
CVE-2015-1635_PoC
MS15-034
CVE-2015-1635
CVE-2015-1635-POC
HTTPsys
CVE-2015-1635
Exploit for Code Injection in Microsoft
MS15-034 HTTP Protocol Stack Request Handling HTTP.SYS Memory Information Disclosure
MS15-034 HTTP Protocol Stack Request Handling Denial-of-Service
Exploit for Code Injection in Microsoft
Exploit for Code Injection in Microsoft
Exploit for Code Injection in Microsoft
Exploit for Code Injection in Microsoft
IIS 系列 Http.sys 处理 Range 整数溢出漏洞
MS15-034 HTTP Protocol Stack Request Handling HTTP.SYS Memory Information Disclosure
MS15-034 Microsoft IIS Remote Code Execution Exploit
Microsoft Window (HTTP.sys) HTTP Request Parsing DoS (MS15-034)
Microsoft Windows - 'HTTP.sys' HTTP Request Parsing Denial of Service (MS15-034)
Microsoft Windows HTTP.sys Proof Of Concept
MS15-034 HTTP Protocol Stack Request Handling Denial-of-Service
Microsoft Window - HTTP.sys PoC (MS15-034)
Microsoft Windows - 'HTTP.sys' (PoC) (MS15-034)
Exploit for Code Injection in Microsoft
CVE-2015-1635