CVE-2015-1635: Microsoft HTTP.sys Remote Code Execution Vulnerability
Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.
Other sources
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1635?
CVE-2015-1635 has a critical severity rating as it allows remote code execution.
How do I fix CVE-2015-1635?
To fix CVE-2015-1635, you should apply the latest patches and updates provided by Microsoft for the affected operating systems.
Which versions of Windows are affected by CVE-2015-1635?
CVE-2015-1635 affects Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2008 R2 SP1, and Windows Server 2012.
How is CVE-2015-1635 exploited?
CVE-2015-1635 can be exploited by remote attackers who send specially crafted requests to the HTTP.sys component.
What components are involved in CVE-2015-1635?
CVE-2015-1635 involves the Microsoft HTTP protocol stack, specifically the HTTP.sys driver.