⚠ Actively exploited
Added to CISA KEV on 2022-03-28. Federal agencies required to patch by 2022-04-18. Required action: Apply updates per vendor instructions..

CVE-2015-2419Out-of-bounds Write in Microsoft Internet Explorer

Severity
8.8HIGHNVD
EPSS
69.4%
top 1.34%
CISA KEV
KEV
Added 2022-03-28
Due 2022-04-18
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedJul 14
KEV addedMar 28
KEV dueApr 18
Latest updateMay 14
CISA Required Action: Apply updates per vendor instructions.

Description

JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability."

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-pv3m-j6rc-qgg4: JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption)2022-05-14
CVEList
CVE-2015-2419: JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption)2015-07-14
VulnCheck
Microsoft Internet Explorer Memory Corruption Vulnerability2015

💥Exploits & PoCs

1
Exploit-DB
Microsoft Internet Explorer 11 - javascript Code Execution2016-02-01

🔍Detection Rules

2
Suricata
ET EXPLOIT_KIT Terror EK CVE-2015-2419 Exploit2017-04-04
Suricata
ET EXPLOIT CVE-2015-2419 As observed in Magnitude EK2016-09-21

📋Vendor Advisories

1
CISA
Microsoft Internet Explorer Memory Corruption Vulnerability2022-03-28

🕵️Threat Intelligence

17
Tenable
How VPR Helped Prioritize the Most Dangerous CVEs in 20192020-04-30
Trendmicro
Capesand verwendet öffentliche Exploits und Tools2019-11-07
Trendmicro
New Capesand Exploit Kit Reuses Public Exploits, Tools2019-11-05
Trendmicro
New Capesand Exploit Kit Reuses Public Exploits, Tools2019-11-05
Trendmicro
Down but Not Out: Recent Exploit Kit Activities2018-07-02
CVE-2015-2419 — Out-of-bounds Write in Microsoft | cvebase