Vulnerability record · CVE-2015-2419 · published 14 July 2015
CVE-2015-2419: Microsoft Internet Explorer JScript9 memory corruption RCE
Microsoft · Internet Explorer
JScript 9 in Internet Explorer 10 and 11 contains an out-of-bounds write that corrupts memory when processing a crafted web page. Successful exploitation allows arbitrary code execution in the context of the browser, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with no privileges required, high EPSS, and confirmed KEV listing make this a high-priority patching target despite the age of the affected browser.
What it is
JScript 9 in Internet Explorer 10 and 11 contains an out-of-bounds write that corrupts memory when processing a crafted web page. Successful exploitation allows arbitrary code execution in the context of the browser, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker can execute arbitrary code with the privileges of the IE process or crash the browser, giving a foothold on the victim host.
Attack surface
Reached over the network by luring a user to a crafted web site; no authentication is required but user interaction (visiting the page) is needed per the CVSS vector.
Exploitation
Listed in CISA KEV since 2022-03-28 with a required action to apply vendor updates, and EPSS shows a high 30-day probability (0.534, ~98.9th percentile), indicating active exploitation is expected.
What to do
- Apply the Microsoft MS15-065 security update for Internet Explorer 10 and 11.
- Retire or restrict Internet Explorer where possible and migrate users to a supported browser.
- Enforce EMET or Exploit Protection mitigations on remaining IE deployments.
- Block or filter untrusted web content and restrict browsing to approved sites.
Detection
- Monitor for IE process crashes or unexpected child processes spawned by iexplore.exe.
- Hunt for suspicious script or shellcode activity originating from browser processes.
- Review proxy and DNS logs for access to known exploit or malvertising hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-2419 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Microsoft Internet Explorer Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securitytracker.com/id/1032894 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-065 | PatchVendor Advisory |
| http://www.securitytracker.com/id/1032894 | Broken LinkThird Party AdvisoryVDB Entry |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-065 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2419 | US Government Resource |
Track CVE-2015-2419 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-2419), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.