CVE-2015-2444
Microsoft Internet Explorer 8-11 - Remote Code Execution via Memory Corruption
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-2444. PoCs published by Blue Frost Security GmbH.
AI-analyzed exploit summary This is a proof-of-concept exploit for CVE-2015-2444, a use-after-free vulnerability in Microsoft Internet Explorer's MSHTML!CTreeNode::GetCascadedLang function. The HTML/JS code triggers the vulnerability by manipulating DOM elements, leading to a crash that could potentially allow arbitrary code execution.
Description
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2442.
Exploits (1)
This is a proof-of-concept exploit for CVE-2015-2444, a use-after-free vulnerability in Microsoft Internet Explorer's MSHTML!CTreeNode::GetCascadedLang function. The HTML/JS code triggers the vulnerability by manipulating DOM elements, leading to a crash that could potentially allow arbitrary code execution.