CVE-2015-0071

microsoft internet explorer

Published 11 Feb 2015 · updated 17 Jun 2026 · Analyzed

6.5 Medium · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 25 May 2022, with a remediation deadline of 15 Jun 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."

References