CVE-2015-0040

Microsoft Internet Explorer 11 - Remote Code Execution or Denial of Service via Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-0040. PoCs published by Skylined.

AI-analyzed exploit summary This PoC exploits a reentrancy issue in MSIE 11's handling of readystatechange events, leading to a use-after-free vulnerability via CMapElement object manipulation. The exploit triggers memory corruption by interrupting DOM notifications during applet element insertion.

Description

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0018, CVE-2015-0037, and CVE-2015-0066.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Skylined · doswindows
https://www.exploit-db.com/exploits/40757

This PoC exploits a reentrancy issue in MSIE 11's handling of readystatechange events, leading to a use-after-free vulnerability via CMapElement object manipulation. The exploit triggers memory corruption by interrupting DOM notifications during applet element insertion.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: Microsoft Internet Explorer 11
No auth needed
Prerequisites: Target must visit a malicious webpage · JavaScript must be enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/539752/100/0/threaded
Various Sources x_refsource_misc
http://blog.skylined.nl/20161114001.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72410
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031723
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/40757/

Scores

EPSS 0.3004
EPSS Percentile 98.0%

Details

CWE
CWE-399
Status published
Products (1)
microsoft/internet_explorer 11
Published Feb 11, 2015
Tracked Since Feb 18, 2026