CVE-2015-1635
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft HTTP.sys Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-94
מוצרים מושפעים
microsoft: windows 7; microsoft: windows 8; microsoft: windows 8.1; microsoft: windows server 2008; microsoft: windows server 2012
קישורים
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-… PatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-… PatchVendor Advisory
- http://packetstormsecurity.com/files/131463/Microsoft-Windows-HTTP.sys-Proof-O… ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/36773/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/36776/ ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/131463/Microsoft-Windows-HTTP.sys-Proof-O… ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/36773/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/36776/ ExploitThird Party AdvisoryVDB Entry
- http://www.osvdb.org/120629 Broken Link
- http://www.securityfocus.com/bid/74013 Broken LinkThird Party AdvisoryVDB Entry