ZeroHour

CVE-2015-2502

KEVmass

Memory Corruption Remote Code Execution in Microsoft Internet Explorer

CISA: Microsoft Internet Explorer Memory Corruption Vulnerability

CVSS
EPSS
51%p99
Published
KEV added
AI analysis

CVE-2015-2502 is a memory corruption flaw (CWE-119) in Microsoft Internet Explorer in which the browser mishandles specially crafted web content, allowing an attacker to execute code or crash the browser (denial of service). It is triggered when a user of an affected IE version visits an attacker-controlled page, typically delivered via phishing email, a compromised website, or a malicious ad; no special privileges or configuration are required beyond normal web browsing. Successful exploitation yields code execution in the context of the current user, so an admin-rights user exposes the whole system, while the impact is contained for lower-privileged accounts. Affected parties are users of the Microsoft Internet Explorer versions addressed by Microsoft's out-of-band advisory, which in practice means unpatched legacy Windows systems still relying on IE (intranet apps, kiosks, and enterprise fleets using legacy web applications). The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-13), confirming in-the-wild exploitation; EPSS assigns a ~51% probability of exploitation within 30 days (99th percentile), and no public PoC is known.

What to do: Apply Microsoft's cumulative Internet Explorer security update from the out-of-band advisory to every Windows system, per the CISA KEV required action, prioritizing internet-facing or multi-user hosts. Migrate any remaining IE-dependent systems and intranet applications to a modern browser (e.g., Microsoft Edge with IE mode), since IE is end-of-life and unpatched instances are a routine attacker entry point. If legacy systems cannot be patched promptly, restrict IE usage and harden browsing (Restricted Sites zone, enhanced security configurations); ransomware linkage is unknown but treat unpatched IE as a general foothold risk.

Affected
Microsoft Internet Explorer
Estimated exposure
masshundreds of millions of Windows/IE users and installations (IE was the default browser on essentially all Windows PCs of the era) — Internet Explorer shipped by default with effectively every supported Windows installation during the 2015 patch window, and legacy Windows systems running unpatched or since-retired IE remain widespread in enterprise estates, implying a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Internet Explorer
Weakness
CWE-119

In the news