CVE-2015-2419
HIGH KEV RANSOMWAREInternet Explorer 10 and 11 - Remote Code Execution via JScript9 Memory Corruption
Title source: llmExploitation Summary
CVE-2015-2419 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 28, 2022, with confirmed use in ransomware campaigns. EIP tracks 1 public exploit from researchers including checkpoint.
AI-analyzed exploit summary This exploit leverages a use-after-free vulnerability in Microsoft Internet Explorer (CVE-2015-2419) to achieve remote code execution. It employs heap spraying, memory corruption, and ROP chains to bypass DEP and execute arbitrary shellcode (e.g., launching calc.exe).
Description
JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability."
Exploits (1)
This exploit leverages a use-after-free vulnerability in Microsoft Internet Explorer (CVE-2015-2419) to achieve remote code execution. It employs heap spraying, memory corruption, and ROP chains to bypass DEP and execute arbitrary shellcode (e.g., launching calc.exe).
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H