CVE-2015-0032
Microsoft VBScript 5.6-5.8 - Remote Code Execution via Memory Corruption
Title source: llmDescription
vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 8 through 11 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerability."
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/72910
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-018
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1031888
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-019
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1031887
Scores
EPSS
0.2232
EPSS Percentile
97.4%
Details
CWE
CWE-399
Status
published
Products (7)
microsoft/internet_explorer
8
microsoft/internet_explorer
9
microsoft/internet_explorer
10
microsoft/internet_explorer
11
microsoft/vbscript
5.6
microsoft/vbscript
5.7
microsoft/vbscript
5.8
Published
Mar 11, 2015
Tracked Since
Feb 18, 2026