CyberSec.Space Logo
Back to CVE Browser

CVE-2015-1635

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score46.6400%
EPSS Percentile86.02th
PublishedApr 14, 2015
Last ModifiedApr 22, 2026

Vulnerability Description

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."

Affected Platforms (CPE)

πŸ’»
Microsoft

Windows 7

All versions
πŸ’»
Microsoft

Windows 8

All versions
πŸ’»
Microsoft

Windows 8.1

All versions
πŸ’»
Microsoft

Windows Server 2008

= r2
πŸ’»
Microsoft

Windows Server 2008

= r2
πŸ’»
Microsoft

Windows Server 2012

All versions
πŸ’»
Microsoft

Windows Server 2012

= r2

References & Advisories

Related Vulnerabilities