CVE-2015-1635
Microsoft HTTP.sys Remote Code Execution Vulnerability
9.8
CVSS 3.1
100.0 %
EPSS (current)
2022-02-10
KEV addition
No
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: Microsoft / HTTP.sys
Published: 2015-04-14 · Due (CISA): 2022-08-10
CWE: CWE-94 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| metasploit | auxiliary/dos/http/ms15_034_ulonglongadd | auxiliary/dos/http/ms15_034_ulonglongadd | – |
| metasploit | auxiliary/scanner/http/ms15_034_http_sys_memory_dump | auxiliary/scanner/http/ms15_034_http_sys_memory_dump | – |
| nuclei | http/cves/2015/CVE-2015-1635.yaml | Microsoft Windows 'HTTP.sys' - Remote Code Execution | – |
| exploitdb | 36773 | Microsoft Windows - 'HTTP.sys' (PoC) (MS15-034) | 2015-04-15 |
| exploitdb | 36776 | Microsoft Windows - 'HTTP.sys' HTTP Request Parsing Denial of Service (MS15-034) | 2015-04-16 |
References only — no downloads or instructions.