Web Hack List

Other nomination

IE11 RCE

Microsoft shipped the out-of-band bulletin MS15-093 for CVE-2015-2502, a memory-corruption flaw in how Internet Explorer 7 to 11 handles objects in memory. A crafted or compromised web page, ad or HTML email runs attacker code with the current user's rights, was already being exploited in the wild, and can be chained with other bugs to reach administrator.

Record

Researcher
Mike Lennon and @SecurityWeek
Published by
SecurityWeek
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Mike Lennon and @SecurityWeek, first published at the original source. Preserved copies are kept so the citation survives its host.