HTTP.sys (IIS) DoS And Remote Code Execution
Description: Denial of Service (DoS) exploits are widely available to exploit CVE-2015-1635, a vulnerability in HTTP.sys, affecting Internet Information Server (IIS). The patch was released on Tuesday (April 14th) as part of Microsoft's Patch Tuesday. Due to the ease with which this vulnerability can be exploited, we recommend that you expedite patching this vulnerability. Risk Critical CVSS Score 10.0 CVE CVE-2015-1635 Proof of Concept: Method 1: Download nmap script from the following https://github.com/pr4jwal/quick-scripts/blob/master/ms15-034.nse Save the file in the script folder (/usr/share/nmap/scripts/) If the server is vulnerable it will show the following.