PT-2015-2986 · Microsoft · Internet Explorer+2

Published

2015-10-13

·

Updated

2018-10-12

·

CVE-2015-6059

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Internet Explorer versions 8 through 11 VBScript versions 5.7 and 5.8 JScript versions 5.7 and 5.8
Description The issue is related to the improper disclosure of memory contents by the JScript or VBScript engines, potentially allowing remote attackers to obtain sensitive information from process memory via a crafted web site. An attacker must know the memory address of where the object was created to exploit this issue.
Recommendations For Internet Explorer versions 8 through 11, update the scripting engines to a non-vulnerable version. For VBScript versions 5.7 and 5.8, consider disabling the scripting engine until a patch is available. For JScript versions 5.7 and 5.8, restrict access to sensitive data to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00190
CVE-2015-6059

Affected Products

Internet Explorer
Jscript
Vbscript