Microsoft Internet Explorer Out of Band Advisory
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2015-2502 | Memory Corruption Remote Code Execution in Microsoft Internet Explorer CVE-2015-2502 is a memory corruption flaw (CWE-119) in Microsoft Internet Explorer in which the browser mishandles specially crafted web content, allowing an attacker to execute code or crash the browser (denial of service). It is triggered when a user of an affected IE version visits an attacker-controlled page, typically delivered via phishing email, a compromised website, or a malicious ad; no special privileges or configuration are required beyond normal web browsing. Successful exploitation yields code execution in the context of the current user, so an admin-rights user exposes the whole system, while the impact is contained for lower-privileged accounts. Affected parties are users of the Microsoft Internet Explorer versions addressed by Microsoft's out-of-band advisory, which in practice means unpatched legacy Windows systems still relying on IE (intranet apps, kiosks, and enterprise fleets using legacy web applications). The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-13), confirming in-the-wild exploitation; EPSS assigns a ~51% probability of exploitation within 30 days (99th percentile), and no public PoC is known. Do: Apply Microsoft's cumulative Internet Explorer security update from the out-of-band advisory to every Windows system, per the CISA KEV required action, prioritizing internet-facing or multi-user hosts. Migrate any remaining IE-dependent systems and intranet applications to a modern browser (e.g., Microsoft Edge with IE mode), since IE is end-of-life and unpatched instances are a routine attacker entry point. If legacy systems cannot be patched promptly, restrict IE usage and harden browsing (Restricted Sites zone, enhanced security configurations); ransomware linkage is unknown but treat unpatched IE as a general foothold risk. | — | 51% | KEV |
| masshundreds of millions of Windows/IE users and installations (IE was the default browser on essentially all Windows PCs of the era) |
Full article251 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, August 18, 2015 16:33
Today an out of band advisory was released by Microsoft to address CVE-2015-2502. This vulnerability is addressed by MS15-093.
MS15-093 address a memory corruption vulnerability in Internet Explorer versions 7, 8, 9, 10, and 11. This affects all currently supported versions of Windows, including Windows 10.
This advisory is rated critical. An attacker can craft a web page designed to exploit this vulnerability and lure a user into visiting it. The compromise will result in remote code execution at the permission level of the affected user. The use of proper user access controls can limit the severity of the compromise.
As with most out of band releases, it has been reported that this attack is being exploited in the wild. Users should patch immediately.
Coverage
In response to this bulletin disclosure, Talos has released the following rules to address this vulnerability. Please note that additional rules may be released at a future date and current rules are subject to change pending additional vulnerability information. For the most current rule information, please refer to your Defense Center, FireSIGHT Management Center or Snort.org.
Snort SIDs: 35536-35537

Advanced Malware Protection (AMP) is ideally suited to prevent the execution of the malware used by these threat actors.
CWSand WSA web scanning prevents access to malicious websites, including the downloading of the malware downloaded during these attacks.
The Network Security protection of IPS and NGFW have up-to-date rules to detect malicious network activity by threat actors.
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/microsoft-internet-explorer-out-of-band/