Junglewise Threat Intelligence

CVE-2015-2425: Microsoft Internet Explorer Memory Corruption Vulnerability

CVE-2015-2425 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-05-25

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

Microsoft Internet Explorer 11 contains a memory corruption vulnerability (specifically an out-of-bounds write) that allows remote attackers to execute arbitrary code or cause a denial of service via a crafted website. This vulnerability has been observed being exploited in the wild.

Affected products

  • Microsoft Internet Explorer 11 11

Timeline

  • 2015-07-14: advisory: Microsoft Security Bulletin MS15-065 published
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-25: disclosed: NVD publication date

Related threats