PT-2015-1061 · Microsoft · Internet Explorer
Published
2015-04-14
·
Updated
2018-10-12
·
CVE-2015-1661
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Internet Explorer versions 6 through 11
Description
The issue is related to a security feature bypass vulnerability in the Address Space Layout Randomization (ASLR) mechanism. This vulnerability allows an attacker to more reliably predict memory offsets, which could be used in conjunction with another vulnerability to execute arbitrary code. The ASLR bypass by itself does not allow code execution but can be used to increase the reliability of exploiting other vulnerabilities.
Recommendations
For Internet Explorer versions 6 through 11, consider disabling the ASLR bypass vulnerability as a temporary workaround until a patch is available. However, since the provided information does not specify a fixed version or a direct patch for this issue, and given the nature of the vulnerability, restricting access to potentially vulnerable web sites or modules could help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer