MS15-034 – Range Header Integer Overflow
ID: 21db75f0-d0f8-52da-82a0-e18a0573c292
STIX ID: report--21db75f0-d0f8-52da-82a0-e18a0573c292
Feed Name: TrustedSec blog
Threat Score
This report details Microsoft vulnerability MS15-034 in HTTP.sys where an oversized Range header can overflow a 64-bit integer, potentially enabling kernel-level memory corruption and remote code execution on IIS/HTTP.sys-using systems; it includes detection methods (netstat, curl, a Python PoC), a local patch-check command (wmic qfe | find "KB3042553"), lists affected Windows versions, and advises immediate patching of public-facing assets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
