Junglewise Threat Intelligence

CVE-2015-0071: Microsoft Internet Explorer ASLR Bypass Vulnerability

CVE-2015-0071 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2022-05-25

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

Microsoft Internet Explorer 9 through 11 contains a vulnerability that allows remote attackers to bypass the Address Space Layout Randomization (ASLR) protection mechanism. An attacker can exploit this by tricking a user into visiting a specially crafted website.

Affected products

  • Microsoft Internet Explorer 9 through 11

Timeline

  • 2015-02-10: patched: Microsoft released security bulletin MS15-009 to address the issue.
  • 2022-05-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.

Related threats