CVE-2015-1712: Buffer Overflow
Published May 13, 2015
·Updated
Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1691.
Affected Software
2 affected components
Microsoft Internet Explorer=8
Microsoft Internet Explorer=9
Event History
May 13, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
Which systems are exposed to this vulnerability?
Systems using Microsoft Internet Explorer 8 or 9 are affected. The issue is remotely reachable through a crafted website, so exposure exists when users browse to attacker-controlled or compromised web content.
2
What does an attacker need to exploit it?
An attacker does not need authentication. They need to induce a user to access a crafted website, which can trigger memory corruption and lead to arbitrary code execution or denial of service.