PT-2015-2036 · Microsoft · Internet Explorer 8+1

Publicado

2015-09-08

·

Atualizado

2018-10-12

·

CVE-2015-2493

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Internet Explorer 8
Description The issue is related to the VBScript and JScript engines in Internet Explorer, which can allow remote attackers to execute arbitrary code or cause a denial of service due to memory corruption via a crafted web site. This is caused by a buffer overflow in the implementation of these scripting engines. An attacker who successfully exploits the issue could gain the same user rights as the current user, potentially taking control of an affected system if the current user has administrative rights. This could enable the attacker to install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations For Internet Explorer 8, consider applying security updates or patches that address the scripting engine memory corruption issue to prevent remote code execution and denial of service attacks. As a temporary workaround, consider restricting the use of VBScript and JScript engines in Internet Explorer until a patch is available.

Correção

RCE

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-11382
CVE-2015-2493

Produtos afetados

Internet Explorer
Internet Explorer 8