KEVIntel
9.8
CVSS
Critical

CVE-2015-1635

PUBLISHED

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote...

Exploited in the wild Remote Low complexity No user interaction
Vendor
Microsoft
Product
Windows
Published
Apr 14, 2015
EPSS

Description

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."

windows cisa nuclei_scanner

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 10.0

AV:N/AC:L/Au:N/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2022-02-10 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Feb 10, 2022

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

Cappricio-Securities/CVE-2015-1635

github · Created 2024-05-28 10:41:07 UTC · 0 stars

Microsoft Windows 'HTTP.sys' - Remote Code Execution

w01ke/CVE-2015-1635-POC

github · Created 2022-04-17 16:48:44 UTC · 1 stars

CVE-2015-1635-POC,指定IP与端口验证HTTP.sys漏洞是否存在

n3rdh4x0r/CVE-2015-1635

github · Created 2021-07-12 00:37:54 UTC · 0 stars

n3rdh4x0r/CVE-2015-1635-POC

github · Created 2021-07-12 00:23:30 UTC · 2 stars

limkokholefork/CVE-2015-1635

github · Created 2018-08-02 11:28:14 UTC · 1 stars

MS15-034: HTTP.sys (IIS) DoS

aedoo/CVE-2015-1635-POC

github · Created 2018-06-20 14:28:11 UTC · 7 stars

MS15-034 HTTP.sys 远程执行代码检测脚本(MS15-034 HTTP.sys remote execution code poc script)

Zx7ffa4512-Python/Project-CVE-2015-1635

github · Created 2015-04-16 07:31:47 UTC · 2 stars

CVE-2015-1635,MS15-034

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei