Website Security & Threat Management
Protection against critical Windows vulnerability (CVE-2015-1635)

Protection against critical Windows vulnerability (CVE-2015-1635)

4/15/2015 · Ben Cartwright-Cox

What this post added

This post details the immediate deployment of a Web Application Firewall (WAF) rule to block requests exploiting the MS15-034 vulnerability in Windows servers. The rule specifically targets HTTP Range headers with large byte offsets, which were known to cause Denial of Service (DoS) or Remote Code Execution (RCE) on vulnerable systems. Customers on paid plans with WAF enabled are automatically protected.

Read the original post ↗