Windows kernel level HTTP driver http.sys
is affected by remote code execution vulnerability (MS15-034).
This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker sends a specially crafted HTTP request to an affected Windows system.
This security update is rated Critical for all supported editions of Windows 7, Windows Server 2008 R2, Windows 8, Windows Server 2012, Windows 8.1, and Windows Server 2012 R2.
What's not clear to me is if http.sys
would be running and listening on a Windows machine, which does not have web server installed?
Post on installing nginx on Windows would suggest that http.sys
is running regardless. Is that the case or would it be disabled by default on desktop Windows versions?