Critical severity9.8CISA KEVNVD Advisory· Published Apr 14, 2015· Updated Apr 22, 2026
CVE-2015-1635
CVE-2015-1635
Description
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."
Affected products
7- cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*+ 1 more
- cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*
- cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-034nvdPatchVendor Advisory
- packetstormsecurity.com/files/131463/Microsoft-Windows-HTTP.sys-Proof-Of-Concept.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/36773/nvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/36776/nvdExploitThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/74013nvdThird Party AdvisoryVDB EntryBroken Link
- www.securitytracker.com/id/1032109nvdThird Party AdvisoryVDB EntryBroken Link
- www.osvdb.org/120629nvdBroken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.