PT-2015-1061 · Microsoft · Internet Explorer

Published

2015-04-14

·

Updated

2018-10-12

·

CVE-2015-1661

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Internet Explorer versions 6 through 11
Description The issue is related to a security feature bypass vulnerability in the Address Space Layout Randomization (ASLR) mechanism. This vulnerability allows an attacker to more reliably predict memory offsets, which could be used in conjunction with another vulnerability to execute arbitrary code. The ASLR bypass by itself does not allow code execution but can be used to increase the reliability of exploiting other vulnerabilities.
Recommendations For Internet Explorer versions 6 through 11, consider disabling the ASLR bypass vulnerability as a temporary workaround until a patch is available. However, since the provided information does not specify a fixed version or a direct patch for this issue, and given the nature of the vulnerability, restricting access to potentially vulnerable web sites or modules could help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09916
CVE-2015-1661
ZDI-15-127

Affected Products

Internet Explorer