VBScript ASLR Bypass in Microsoft IE & VBScript Engine
CVE-2015-1684

Currently unrated

Key Information:

Vendor
Microsoft
Status
Vendor
CVE Published:
13 May 2015

Summary

The vulnerability exists in the VBScript.dll component of the Microsoft VBScript engine versions 5.6 through 5.8, utilized in Internet Explorer versions 8 through 11 and other Microsoft products. A remote attacker could exploit this flaw to bypass the ASLR protection mechanism by crafting a malicious website. This allows the attacker to execute arbitrary code on the affected system, potentially compromising user data and security.

References

EPSS Score

12% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2015-1684 : VBScript ASLR Bypass in Microsoft IE & VBScript Engine | SecurityVulnerability.io