Oval Definition:oval:org.cisecurity:def:451
Revision Date:2016-04-29Version:38
Title:Memory Corruption Vulnerability – CVE-2015-2502 (MS15-093)
Description:Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2015-2502
Platform(s):Microsoft Windows 10
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Vista
Product(s):Microsoft Internet Explorer 10
Microsoft Internet Explorer 11
Microsoft Internet Explorer 7
Microsoft Internet Explorer 8
Microsoft Internet Explorer 9
Definition Synopsis
  • IE7 is installed + Windows OS + file version
  • Microsoft Internet Explorer 7 is installed
  • AND Microsoft Windows Vista/Server 2008 is installed
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows Server 2008 (ia-64) is installed
  • AND Check for file version
  • Check if mshtml.dll version is less than 7.0.6002.19475
  • OR Check for Limited Distribution Release (LDR) file version
  • Check if mshtml.dll version is greater than or equal to 7.0.6002.23000
  • AND Check if mshtml.dll version is less than 7.0.6002.23782
  • OR IE8 is installed + Windows OS + file version
  • Microsoft Internet Explorer 8 is installed
  • AND Windows OS is installed + file version
  • Microsoft Windows Vista/Server 2008 is installed + file version
  • Microsoft Windows Vista/Server 2008 is installed
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • AND Check for file version
  • Check if mshtml.dll version is less than 8.0.6001.19674
  • OR Microsoft Windows 7/Server 2008 R2 is installed + file version
  • Microsoft Windows 7/Server 2008 R2 is installed
  • Microsoft Windows 7 (32-bit) is installed
  • OR Microsoft Windows 7 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed
  • AND Check for file version
  • Check if mshtml.dll version is less than 8.0.7601.18968
  • OR IE9 is installed + Windows OS + file version
  • Microsoft Internet Explorer 9 is installed
  • AND Microsoft Windows Vista/Server 2008/7/Server 2008 R2 is installed
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows 7 (32-bit) is installed
  • OR Microsoft Windows 7 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 x64 Edition is installed
  • AND Check for file version
  • Check if mshtml.dll version is less than 9.0.8112.16685
  • OR Check for Limited Distribution Release (LDR) file version
  • Check if mshtml.dll version is greater than or equal to 9.0.8112.20000
  • AND Check if mshtml.dll version is less than 9.0.8112.20800
  • OR IE10 is installed + Windows OS + file version
  • Microsoft Internet Explorer 10 is installed
  • AND Microsoft Windows 7/Server 2008 R2/8/Server 2012 is installed
  • Microsoft Windows 7 (32-bit) is installed
  • OR Microsoft Windows 7 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 x64 Edition is installed
  • OR Microsoft Windows 8 (x86) is installed
  • OR Microsoft Windows 8 (x64) is installed
  • OR Microsoft Windows Server 2012 (64-bit) is installed
  • AND Check for file version
  • Check if mshtml.dll version is less than 10.0.9200.17479
  • OR Check for Limited Distribution Release (LDR) file version
  • Check if mshtml.dll version is greater than or equal to 10.0.9200.21000
  • AND Check if mshtml.dll version is less than 10.0.9200.21595
  • OR IE11 is installed + Windows OS + file version
  • Microsoft Internet Explorer 11 is installed
  • AND Windows OS is installed + file version
  • Microsoft Windows 7/Server 2008 R2/8.1/Server 2012 R2 is installed + file version
  • Microsoft Windows 7/Server 2008 R2/8.1/Server 2012 R2 is installed
  • Microsoft Windows 7 (32-bit) is installed
  • OR Microsoft Windows 7 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 x64 Edition is installed
  • OR Microsoft Windows 8.1 (x86) is installed
  • OR Microsoft Windows 8.1 (x64) is installed
  • OR Microsoft Windows Server 2012 R2 is installed
  • AND Check if mshtml.dll version is less than 11.0.9600.17963
  • OR Microsoft Windows 10 is installed + file version
  • Microsoft Windows 10 is installed
  • Microsoft Windows 10 (32-bit) is installed
  • OR Microsoft Windows 10 (64-bit) is installed
  • AND Check if mshtml.dll version is less than 11.0.10240.16445
  • BACK