Junglewise Threat Intelligence

CVE-2015-1635: Microsoft HTTP.sys Remote Code Execution Vulnerability

CVE-2015-1635 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-02-10

Technologies: Microsoft Windows 8.1. Vendors: Microsoft.

Executive brief

The HTTP protocol stack (HTTP.sys) in multiple Microsoft Windows operating systems allows remote attackers to execute arbitrary code via specially crafted HTTP requests. This vulnerability is caused by improper control of generation of code (code injection) within the stack.

Affected products

  • Microsoft Windows 7 SP1
  • Microsoft Windows Server 2008 R2 SP1
  • Microsoft Windows 8
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2012 Gold and R2

Timeline

  • 2015-04-14: advisory: Microsoft Security Bulletin MS15-034 published.
  • 2022-02-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-02-10: disclosed: NVD publication date.
  • 2022-08-10: other: CISA due date for remediation.