CVE-2015-1635 is a critical remote code execution vulnerability in the Windows HTTP protocol stack, HTTP.sys, affecting Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012, and Windows Server 2012 R2. The flaw is caused by improper input parsing that can lead to a buffer overflow when HTTP.sys processes a specially crafted HTTP request, including malformed HTTP Range header values. Because HTTP.sys operates in the kernel and services HTTP requests on behalf of IIS and other HTTP.sys-based applications, successful exploitation can occur before the request reaches the application layer. The vulnerability is reachable remotely over the network without authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
This repository contains a single Metasploit auxiliary scanner module targeting the MS15-034 vulnerability (CVE-2015-1635) in Microsoft Windows HTTP.SYS. The exploit leverages a flaw in the handling of HTTP Range headers to trigger an information disclosure, allowing remote attackers to dump memory from the HTTP.SYS process. The module is written in Ruby and is designed to be run within the Metasploit Framework. It supports scanning and exploitation of Windows 8.1, Server 2012, and Server 2012R2 systems. The module attempts to identify valid static files on the target web server (such as /iisstart.htm, /iis-85.png, /welcome.png) to use as the resource for the malicious Range request. If successful, the exploit retrieves and displays a memory dump, which may contain sensitive information. The code is operational and provides a working exploit for the vulnerability, but does not include a customizable payload beyond the information disclosure. The attack vector is network-based, requiring the ability to send HTTP requests to the target system.
This repository contains a single Metasploit auxiliary module (modules/auxiliary/dos/http/ms15_034_ulonglongadd.rb) targeting the MS15-034 vulnerability (CVE-2015-1635) in Microsoft's HTTP.sys. The module is designed to check for and exploit a denial-of-service (DoS) condition in the HTTP protocol stack by sending a specially crafted HTTP Range header with an extremely large upper bound. The exploit works by first probing the target for a valid static file resource, then sending the malicious Range request to trigger the vulnerability. If successful, the HTTP service on the target system will crash, resulting in a DoS. The code is written in Ruby and leverages Metasploit's auxiliary, scanner, and DoS modules. The only fingerprintable endpoint is the HTTP URI (default '/'), which can be customized. The module is operational and can be used to test and exploit vulnerable Windows systems running HTTP.sys.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.