CVE-2015-2449: Infoleak
Published Aug 14, 2015
·Updated
Microsoft Internet Explorer 7 through 11 and Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "ASLR Bypass."
Affected Software
6 affected components
Microsoft Internet Explorer=7
Microsoft Internet Explorer=8
Microsoft Internet Explorer=9
Microsoft Internet Explorer=10
Microsoft Internet Explorer=11
Microsoft Edge
Event History
Aug 14, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2449?
CVE-2015-2449 is classified as a critical vulnerability that can allow remote code execution.
2
How do I fix CVE-2015-2449?
To fix CVE-2015-2449, users should apply the security updates provided by Microsoft for their affected versions of Internet Explorer and Edge.
3
Which versions of Internet Explorer are impacted by CVE-2015-2449?
CVE-2015-2449 affects Internet Explorer versions 7 through 11.
4
Can CVE-2015-2449 be exploited through phishing attacks?
Yes, CVE-2015-2449 can be exploited via crafted websites commonly used in phishing attacks.
5
What protections are bypassed by CVE-2015-2449?
CVE-2015-2449 allows attackers to bypass the Address Space Layout Randomization (ASLR) protection mechanism.