CVE-2015-2425
KEVmassMemory Corruption RCE in Microsoft Internet Explorer
CISA: Microsoft Internet Explorer Memory Corruption Vulnerability
Microsoft Internet Explorer contains a memory-corruption flaw (CWE-119) that a remote attacker can trigger when the browser processes crafted web content, resulting in remote code execution or a denial-of-service. A successful exploit would allow the attacker to run arbitrary code in the context of the logged-on user, potentially enabling malware installation or data theft. All deployments of Internet Explorer are potentially affected, although the source data does not specify exact version ranges. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-05-25, and EPSS assigns a 44.9% probability of exploitation within 30 days (99th percentile), though no public PoC is known. CISA's ransomware association for this entry is unknown.
What to do: Apply the Microsoft cumulative security update for Internet Explorer that addresses CVE-2015-2425, per vendor instructions, prioritizing internet-exposed and legacy Windows systems still using IE. Inventory which hosts still run Internet Explorer and which versions are present, and since IE reached end of support on June 15, 2022, migrate remaining users to Microsoft Edge (with IE mode for legacy web apps). Treat the KEV listing as justification for prompt prioritization even though no public PoC is available.
| Microsoft Internet Explorer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
- Affected
- Microsoft Internet Explorer
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Internet Explorer
- Weakness
- CWE-119