High severity8.8CISA KEVNVD Advisory· Published Aug 19, 2015· Updated Apr 22, 2026
CVE-2015-2502
CVE-2015-2502
Description
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.
Affected products
5cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:internet_explorer:11:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-093nvdPatchVendor Advisory
- twitter.com/Laughing_Mantis/statuses/633839231840841728nvdExploit
- www.securityfocus.com/bid/76403nvdBroken LinkThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1033317nvdBroken LinkThird Party AdvisoryVDB Entry
- twitter.com/Laughing_Mantis/statuses/633839771865886721nvdPress/Media Coverage
- www.securityweek.com/microsoft-issues-emergency-patch-critical-ie-flaw-exploited-wildnvdPress/Media Coverage
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.