CVE-2015-2502
microsoft internet explorer
Published 19 Aug 2015 · updated 17 Jun 2026 · Analyzed
8.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 13 Apr 2022, with a remediation deadline of 4 May 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.
References
- twitter.com/Laughing_Mantis/statuses/633839231840841728 · Exploit
- twitter.com/Laughing_Mantis/statuses/633839771865886721 · Press/Media Coverage
- www.securityfocus.com/bid/76403 · Broken Link, Third Party Advisory, VDB Entry
- www.securitytracker.com/id/1033317 · Broken Link, Third Party Advisory, VDB Entry
- www.securityweek.com/microsoft-issues-emergency-patch-critical-ie-flaw-exploited-wild · Press/Media Coverage
- docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-093 · Patch, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2502 · US Government Resource