CVE-2015-1635

Description

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka HTTP.sys Remote Code Execution Vulnerability.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
94.31

Associated Vulnerability

VulnerabilityOS Platform
ms15-034: vulnerability in http.sys could allow remote code execution: april 14, 2015 for Windows 7 (KB3042553)Windows
ms15-034: vulnerability in http.sys could allow remote code execution: april 14, 2015 for Windows 8 (KB3042553)Windows
ms15-034: vulnerability in http.sys could allow remote code execution: april 14, 2015 for Windows 8.1 (KB3042553)Windows
ms15-034: vulnerability in http.sys could allow remote code execution: april 14, 2015 for Windows 7 for x64-based Systems (KB3042553)Windows
ms15-034: vulnerability in http.sys could allow remote code execution: april 14, 2015 for Windows Server 2008 R2 x64 Edition (KB3042553)Windows
ms15-034: vulnerability in http.sys could allow remote code execution: april 14, 2015 for Windows 8 for x64-based Systems (KB3042553)Windows
ms15-034: vulnerability in http.sys could allow remote code execution: april 14, 2015 for Windows Server 2012 (KB3042553)Windows
ms15-034: vulnerability in http.sys could allow remote code execution: april 14, 2015 for Windows 8.1 for x64-based Systems (KB3042553)Windows
ms15-034: vulnerability in http.sys could allow remote code execution: april 14, 2015 for Windows Server 2012 R2 (KB3042553)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-17394Security Update for Windows 7 (KB3042553)
PATCH-17395Security Update for Windows 8 (KB3042553)
PATCH-17396Security Update for Windows 8.1 (KB3042553)
PATCH-17397Security Update for Windows 7 for x64-based Systems (KB3042553)
PATCH-17398Security Update for Windows Server 2008 R2 x64 Edition (KB3042553)
PATCH-17399Security Update for Windows 8 for x64-based Systems (KB3042553)
PATCH-17400Security Update for Windows Server 2012 (KB3042553)
PATCH-17401Security Update for Windows 8.1 for x64-based Systems (KB3042553)
PATCH-17402Security Update for Windows Server 2012 R2 (KB3042553)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234