macOS xterm-256color zsh 678 views

CVE-2015-1635 resides within the HTTP.sys request parsing functionality. The vulnerability stems from improper handling of a specific part of an HTTP request header - the Host header. An attacker could exploit this flaw to inject malicious code into the Host header and potentially execute arbitrary code on the vulnerable system with SYSTEM privileges (the highest level of access in Windows).

To know more about this bug, read the below blog

https://blogs.cappriciosec.com/cve/168/The%20Windows%20HTTP.sys%20Remote%20Code%20Execution%20Flaw%20(CVE-2015-1635)

More recordings by cappriciosec

CVE-2023-27524 0:19

by cappriciosec