Microsoft HTTP.sys Remote Code Execution Vulnerability
n/a — n/a
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."
9.8
100.0%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Published
- Apr 14, 2015
- Modified
- Jun 17, 2026
- Added to KEV
- Feb 10, 2022
- Federal patch due
- Aug 10, 2022
CISA required action
Apply updates per vendor instructions.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2015-1635, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- technion/erlvulnscan★ 10
Concurrent network scanner for CVE-2015-1635
updated Aug 20, 2023
- aedoo/CVE-2015-1635-POC★ 9
MS15-034 HTTP.sys 远程执行代码检测脚本(MS15-034 HTTP.sys remote execution code poc script)
updated Dec 12, 2025
- Zx7ffa4512-Python/Project-CVE-2015-1635★ 2
CVE-2015-1635,MS15-034
updated Sep 25, 2022
- h3x0v3rl0rd/CVE-2015-1635-POC★ 2
updated Jul 31, 2024
- neu5ron/cve_2015-1635★ 1
cve_2015-1635
updated Sep 12, 2015
- bongbongco/MS15-034★ 1
CVE-2015-1635
updated Mar 26, 2019
- Cappricio-Securities/CVE-2015-1635★ 1
Microsoft Windows 'HTTP.sys' - Remote Code Execution
updated Nov 3, 2025
- w01ke/CVE-2015-1635-POC★ 1
CVE-2015-1635-POC,指定IP与端口验证HTTP.sys漏洞是否存在
updated Sep 25, 2022
References
How this class of flaw gets exploited
Frequently asked questions
What is CVE-2015-1635?
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."
How severe is CVE-2015-1635?
CVE-2015-1635 has a CVSS base score of 9.8 out of 10 (CVSS 3.1).
Is CVE-2015-1635 actively exploited in the wild?
Yes. CVE-2015-1635 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Feb 10, 2022, meaning CISA has confirmed evidence of active exploitation.
What is the EPSS score for CVE-2015-1635?
100.0% - meaning FIRST.org's EPSS model estimates a 100.0% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2015-1635?
Yes - a public Nuclei template referencing CVE-2015-1635 exist in public repositories we checked. We also found 8 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2015-1635?
CVE-2015-1635 is classified under CWE-94 (CWE-94 Improper Control of Generation of Code ('Code Injection')).
Cross-checked against
Impactr finds and proves whether CVE-2015-1635 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist