Vulnerability Name:

CVE-2015-6158 (CCN-108278)

Assigned:2015-12-08
Published:2015-12-08
Updated:2018-10-12
Summary:Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6140, CVE-2015-6142, CVE-2015-6143, CVE-2015-6153, CVE-2015-6159, and CVE-2015-6160.
CVSS v3 Severity:9.6 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
8.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-119
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2015-6158

Source: CCN
Type: Microsoft Security Bulletin MS15-124
Cumulative Security Update for Internet Explorer (3116180)

Source: CCN
Type: Microsoft Security Bulletin MS16-001
Cumulative Security Update for Internet Explorer (3124903)

Source: CCN
Type: Microsoft Security Bulletin MS16-009
Cumulative Security Update for Internet Explorer (3134220)

Source: CCN
Type: Microsoft Security Bulletin MS16-023
Cumulative Security Update for Internet Explorer (3142015)

Source: CCN
Type: Microsoft Security Bulletin MS16-037
Cumulative Security Update for Internet Explorer (3148531)

Source: CCN
Type: Microsoft Security Bulletin MS16-051
Cumulative Security Update for Internet Explorer (3155533)

Source: CCN
Type: Microsoft Security Bulletin MS16-063
Cumulative Security Update for Internet Explorer (3163649)

Source: CCN
Type: Microsoft Security Bulletin MS16-084
Cumulative Security Update for Internet Explorer (3169991)

Source: CCN
Type: Microsoft Security Bulletin MS16-095
Cumulative Security Update for Internet Explorer (3177356)

Source: CCN
Type: Microsoft Security Bulletin MS16-104
Cumulative Security Update for Internet Explorer (3183038)

Source: CCN
Type: Microsoft Security Bulletin MS16-118
Cumulative Security Update for Internet Explorer (3192887)

Source: CCN
Type: Microsoft Security Bulletin MS16-120
Security Update for Microsoft Graphics Component (3192884)

Source: CCN
Type: Microsoft Security Bulletin MS16-122
Security Update for Microsoft Video Control (3195360)

Source: CCN
Type: Microsoft Security Bulletin MS16-123
Security Update for Kernel-Mode Drivers (3192892)

Source: CCN
Type: Microsoft Security Bulletin MS16-124
Security Update for Windows Registry (3193227)

Source: CCN
Type: Microsoft Security Bulletin MS16-131
Security Update for Microsoft Video Control (3199151)

Source: CCN
Type: Microsoft Security Bulletin MS16-139
Security Update for Windows Kernel (3199720)

Source: CCN
Type: Microsoft Security Bulletin MS16-142
Cumulative Security Update for Internet Explorer (3198467)

Source: CCN
Type: Microsoft Security Bulletin MS16-144
Cumulative Security Update for Internet Explorer (3204059)

Source: CCN
Type: Microsoft Security Bulletin MS16-155
Security Update for .NET Framework (3205640)

Source: CCN
Type: Microsoft Security Bulletin MS17-006
Cumulative Security Update for Internet Explorer (4013073)

Source: CCN
Type: Microsoft Security Bulletin MS17-013
Security Update for Microsoft Graphics Component (4013075)

Source: SECTRACK
Type: UNKNOWN
1034315

Source: SECTRACK
Type: UNKNOWN
1034316

Source: MS
Type: UNKNOWN
MS15-124

Source: MS
Type: UNKNOWN
MS15-125

Source: XF
Type: UNKNOWN
ms-ie-cve20156158-code-exec(108278)

Source: IDEFENSE
Type: UNKNOWN
20160101 Microsoft Internet Explorer and Edge "Layout_MultiColumnBoxBuilder" Type Confusion Vulnerability

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:edge:-:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_explorer:11:-:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:ie:11:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:edge:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft edge -
    microsoft internet explorer 11 -
    microsoft ie 11
    microsoft edge *