First published: Wed May 13 2015(Updated: )
VBScript.dll in the Microsoft VBScript 5.6 through 5.8 engine, as used in Internet Explorer 8 through 11 and other products, allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "VBScript ASLR Bypass."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft VBScript | =5.6 | |
Microsoft VBScript | =5.7 | |
Microsoft VBScript | =5.8 | |
Internet Explorer | =8 | |
Internet Explorer | =9 | |
Internet Explorer | =10 | |
Internet Explorer | =11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1684 has a critical severity rating due to its potential to allow remote code execution.
To fix CVE-2015-1684, users should apply the security update provided by Microsoft.
CVE-2015-1684 affects Microsoft VBScript versions 5.6 through 5.8 and Internet Explorer versions 8 through 11.
CVE-2015-1684 can be exploited via a crafted website that bypasses the ASLR protection mechanism.
Mitigations for CVE-2015-1684 include disabling the VBScript engine or using an alternative web browser that is not impacted.