Vulnerability Name:

CVE-2015-6135 (CCN-108251)

Assigned:2015-12-08
Published:2015-12-08
Updated:2018-10-12
Summary:The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information Disclosure Vulnerability."
CVSS v3 Severity:3.1 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N)
2.7 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-200
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2015-6135

Source: CCN
Type: Microsoft Security Bulletin MS15-126
Security Update for Microsoft JScript and VBScript to Address Remote Code Execution (3116178)

Source: CCN
Type: Microsoft Security Bulletin MS16-003
Cumulative Security Update for JScript and VBScript to Address Remote Code Execution (3125540)

Source: CCN
Type: Microsoft Security Bulletin MS16-053
Security Update for JScript and VBScript (3156764)

Source: CCN
Type: Microsoft Security Bulletin MS16-069
Cumulative Security Update for Jscript and VBScript (3163640)

Source: CCN
Type: Microsoft Security Bulletin MS16-086
Cumulative Security Update for Jscript and VBScript (3169996)

Source: SECTRACK
Type: UNKNOWN
1034315

Source: SECTRACK
Type: UNKNOWN
1034317

Source: MISC
Type: UNKNOWN
http://www.zerodayinitiative.com/advisories/ZDI-15-586

Source: MS
Type: UNKNOWN
MS15-124

Source: MS
Type: UNKNOWN
MS15-126

Source: XF
Type: UNKNOWN
ms-vbscript-cve20156135-info-disc(108251)

Source: CCN
Type: ZDI-15-586
Microsoft Windows VBScript CreateObject Function Use-After-Free Information Disclosure Vulnerability

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:jscript:5.7:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:jscript:5.8:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:vbscript:5.7:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:vbscript:5.8:*:*:*:*:*:*:*
  • AND
  • cpe:/a:microsoft:internet_explorer:8:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:9:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:10:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:11:-:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:vbscript:5.7:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:vbscript:5.8:*:*:*:*:*:*:*
  • AND
  • cpe:/a:microsoft:internet_explorer:7:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:8:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft jscript 5.7
    microsoft jscript 5.8
    microsoft vbscript 5.7
    microsoft vbscript 5.8
    microsoft internet explorer 8
    microsoft internet explorer 9
    microsoft internet explorer 10
    microsoft internet explorer 11 -
    microsoft vbscript 5.7
    microsoft vbscript 5.8
    microsoft ie 7
    microsoft ie 8