Junglewise Threat Intelligence

CVE-2015-2419: Microsoft Internet Explorer Memory Corruption Vulnerability

CVE-2015-2419 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-28

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

A memory corruption vulnerability exists in the JScript 9 engine within Microsoft Internet Explorer 10 and 11. Remote attackers can exploit this by enticing a user to visit a specially crafted website, leading to arbitrary code execution or a denial of service.

Affected products

  • Microsoft Internet Explorer 10 JScript 9
  • Microsoft Internet Explorer 11 JScript 9

Timeline

  • 2015-07-14: disclosed: NVD Published Date
  • 2015-07-14: patched: Microsoft released security bulletin MS15-065
  • 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-28: exploited: Reported as exploited in the wild per CISA KEV entry

Related threats