Microsoft Windows HTTP.sys Remote Code Execution Vulnerability
Last Update Date:
15 Apr 2015 14:59
Release Date:
15 Apr 2015
4170
Views
RISK: High Risk
TYPE: Operating Systems - Windows OS
A remote code execution vulnerability exists in the HTTP protocol stack (HTTP.sys) that is caused when HTTP.sys improperly parses specially crafted HTTP requests. An attacker who successfully exploited this vulnerability could execute arbitrary code in the context of the System account.
Impact
- Remote Code Execution
System / Technologies affected
- Windows 7
- Windows Server 2008 R2
- Windows 8 and Windows 8.1
- Windows Server 2012 and Windows Server 2012 R2
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/MS15-034
Vulnerability Identifier
Source
Related Link
Share with