PT-2015-2985 · Microsoft · Internet Explorer+2

Published

2015-10-13

·

Updated

2018-10-12

·

CVE-2015-6052

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Internet Explorer versions 8 through 11 VBScript versions 5.7 and 5.8 JScript versions 5.7 and 5.8
Description The issue is related to the VBScript and JScript engines, which allow remote attackers to bypass the Address Space Layout Randomization (ASLR) protection mechanism. This can be achieved via a crafted web site. The ASLR bypass by itself does not allow arbitrary code execution, but it could be used in conjunction with another vulnerability, such as a remote code execution vulnerability, to more reliably run arbitrary code on a target system.
Recommendations For Internet Explorer versions 8 through 11, consider disabling the VBScript and JScript engines until a patch is available. For VBScript versions 5.7 and 5.8, restrict the use of the engine to minimize the risk of exploitation. For JScript versions 5.7 and 5.8, avoid using the engine in conjunction with other potentially vulnerable components. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00189
CVE-2015-6052

Affected Products

Internet Explorer
Jscript
Vbscript