PT-2015-2985 · Microsoft · Internet Explorer+2
Publicado
2015-10-13
·
Atualizado
2018-10-12
·
CVE-2015-6052
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Internet Explorer versions 8 through 11
VBScript versions 5.7 and 5.8
JScript versions 5.7 and 5.8
Description
The issue is related to the VBScript and JScript engines, which allow remote attackers to bypass the Address Space Layout Randomization (ASLR) protection mechanism. This can be achieved via a crafted web site. The ASLR bypass by itself does not allow arbitrary code execution, but it could be used in conjunction with another vulnerability, such as a remote code execution vulnerability, to more reliably run arbitrary code on a target system.
Recommendations
For Internet Explorer versions 8 through 11, consider disabling the VBScript and JScript engines until a patch is available.
For VBScript versions 5.7 and 5.8, restrict the use of the engine to minimize the risk of exploitation.
For JScript versions 5.7 and 5.8, avoid using the engine in conjunction with other potentially vulnerable components.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Internet Explorer
Jscript
Vbscript