Cyber Resilience

CVE-2015-0071

Microsoft Internet Explorer 10 … 9

CISA KEVActive ExploitationEUVD Exploited
Published
11 February 2015
Modified
22 April 2026
KEV Added
25 May 2022
Patch / advisory
CVSS Score v3.1 6.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score 0.34 98th percentile
Risk Priority 76 floored blend · peak EPSS

Summary

CVE-2015-0071 is a medium-severity an unspecified weakness vulnerability in Microsoft Windows Server 2008. Its CVSS base score is 6.5 (Medium).

Operationally, ranked in the top 2% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

Microsoft Internet Explorer versions 9 through 11 contain an ASLR bypass vulnerability that permits remote attackers to circumvent address space layout randomization protections when a user visits a specially crafted website. The flaw is tracked as CVE-2015-0071 and carries a CVSS 3.1 score of 6.5, reflecting network attack vector, low complexity, no required privileges, and user interaction.

An attacker can deliver the exploit through a malicious web page that the victim is induced to load in a vulnerable IE instance. Successful exploitation disables ASLR for the browser process, thereby simplifying follow-on memory corruption attacks that aim to achieve arbitrary code execution or other integrity impacts without altering confidentiality or availability directly.

Microsoft addressed the issue in security bulletin MS15-009, with additional details available from sources such as SecurityFocus bid 72455 and SecurityTracker ID 1031723. No information on observed in-the-wild exploitation is provided in the available references.

EU & UK References

Vulnerability Data

Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."

CWE(s)
KEV Date Added
25 May 2022

Related Threats

CVEs Like This One

CVE-2014-4123Same product: Microsoft Internet Explorerboth on KEV
CVE-2013-7331Same product: Microsoft Internet Explorerboth on KEV
CVE-2014-2817Same product: Microsoft Internet Explorerboth on KEV
CVE-2014-6352Same product: Microsoft Windows 7both on KEV
CVE-2014-4114Same product: Microsoft Windows 7both on KEV
CVE-2015-0016Same product: Microsoft Windows 7both on KEV
CVE-2015-2419Same product: Microsoft Internet Explorerboth on KEV
CVE-2014-1776Same product: Microsoft Internet Explorerboth on KEV
CVE-2014-4148Same product: Microsoft Windows 7both on KEV
CVE-2015-2360Same product: Microsoft Windows 7both on KEV

Affected Assets

microsoft
internet explorer
10, 11, 9

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References