CVE-2015-6052
The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "VBScript and JScript…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "VBScript and JScript ASLR Bypass."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 14.90% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- microsoft/jscript · microsoft/vbscript · microsoft/internet explorer
- Source
- secure@microsoft.com
References
- http://www.securitytracker.com/id/1033800Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-106
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-108
- http://www.securitytracker.com/id/1033800Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-106
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-108
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.