CVE-2015-1686: Infoleak
The Microsoft (1) VBScript 5.6 through 5.8 and (2) JScript 5.6 through 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "VBScript and JScript ASLR Bypass."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1686?
CVE-2015-1686 has a critical severity rating due to its potential to allow remote code execution.
How do I fix CVE-2015-1686?
To fix CVE-2015-1686, you should apply the security update provided by Microsoft for your affected version of Internet Explorer or VBScript.
What versions of Internet Explorer are affected by CVE-2015-1686?
CVE-2015-1686 affects Internet Explorer versions 8, 9, 10, and 11.
Can CVE-2015-1686 be exploited remotely?
Yes, CVE-2015-1686 can be exploited remotely via a specially crafted website.
What is the primary impact of CVE-2015-1686?
The primary impact of CVE-2015-1686 is the potential bypass of Address Space Layout Randomization (ASLR) protection, enabling further attacks.