Junglewise Threat Intelligence

CVE-2015-2502: Microsoft Internet Explorer Memory Corruption Vulnerability

CVE-2015-2502 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-04-13

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

Microsoft Internet Explorer 7 through 11 contains a memory corruption vulnerability (out-of-bounds write) that allows remote attackers to execute arbitrary code or cause a denial of service via a crafted website. This vulnerability was notably exploited in the wild prior to its emergency patching.

Affected products

  • Microsoft Internet Explorer 7 through 11

Timeline

  • 2015-08-18: exploited: Exploited in the wild in August 2015.
  • 2015-08-18: patched: Microsoft issued emergency patch MS15-093.
  • 2022-04-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats