CVE-2015-1684: Infoleak
VBScript.dll in the Microsoft VBScript 5.6 through 5.8 engine, as used in Internet Explorer 8 through 11 and other products, allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "VBScript ASLR Bypass."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1684?
CVE-2015-1684 has a critical severity rating due to its potential to allow remote code execution.
How do I fix CVE-2015-1684?
To fix CVE-2015-1684, users should apply the security update provided by Microsoft.
Which software versions are affected by CVE-2015-1684?
CVE-2015-1684 affects Microsoft VBScript versions 5.6 through 5.8 and Internet Explorer versions 8 through 11.
What type of attack exploits CVE-2015-1684?
CVE-2015-1684 can be exploited via a crafted website that bypasses the ASLR protection mechanism.
Are there any mitigations for CVE-2015-1684?
Mitigations for CVE-2015-1684 include disabling the VBScript engine or using an alternative web browser that is not impacted.