CVE-2015-1635 — Microsoft HTTP.sys Remote Code Execution Vulnerability
2022-02-10 • CISA Known Exploited Vulnerability
[event] Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.
> AFFECTED SOFTWARE
| Field | Value |
|---|---|
| Vendor | Microsoft |
| Product | HTTP.sys |
| CWE | CWE-94 |
| CVE ID | CVE-2015-1635 |
| Date Added | 2022-02-10 |
| Due Date | 2022-08-10 |
| Ransomware Campaign | Unknown |
> MITIGATION
Apply updates per vendor instructions.
Due Date: 2022-08-10