VBScript and JScript Memory Corruption in Microsoft Products
CVE-2015-2482

Currently unrated

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
14 October 2015

What is CVE-2015-2482?

The Microsoft VBScript and JScript engines are vulnerable to exploitation through a crafted replace operation that utilizes JavaScript regular expressions. This flaw can lead to arbitrary code execution or denial of service due to memory corruption, impacting users of Internet Explorer and other affected products. Attackers can leverage this vulnerability to insert malicious scripts that run in the context of the user's session, posing serious risks to data integrity and security.

References

EPSS Score

64% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.