CVE-2015-1635 resides within the HTTP.sys request parsing functionality. The vulnerability stems from improper handling of a specific part of an HTTP request header - the Host header. An attacker could exploit this flaw to inject malicious code into the Host header and potentially execute arbitrary code on the vulnerable system with SYSTEM privileges (the highest level of access in Windows).