PoC Index

CVE-2015-1635

KEVHIGH 10.0EPSS 100.0%

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
100.00% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2022-02-10
Nuclei
critical · CWE-94
Published
2015-04-14
Updated
2025-10-22

Proof-of-concept exploits (35)

Nuclei templates (1)

Metasploit modules (1)

ExploitDB entries (2)

Exploit collections (1)

References

Related