Home / Companies / Cloudflare / Blog / Post Details
Content Deep Dive

Protection against critical Windows vulnerability (CVE-2015-1635)

Blog post from Cloudflare

Post Details
Company
Date Published
Author
Ben Cartwright-Cox
Word Count
106
Company Posts That Month
12
Language
English
Hacker News Points
26
Post removed?
No
Summary

On April 15, 2015, new information emerged about the MS15-034 vulnerability affecting Windows web servers. A proof of concept (PoC) code has been released that can cause a server to hang when it receives an HTTP Range header containing large byte offsets. To address this issue, CloudFlare implemented a Web Application Firewall (WAF) rule blocking such requests. Customers on a paid plan with WAF enabled are automatically protected against this problem. It is strongly advised to update IIS and Windows servers as soon as possible; in the meantime, any attempts to exploit this Denial of Service/Remote Code Execution vulnerability through CloudFlare will be blocked.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.