CVE-2015-0072 is a Universal Cross-Site Scripting (UXSS) vulnerability affecting Microsoft Internet Explorer versions 9 through 11. This flaw allows remote attackers to bypass the Same Origin Policy and inject arbitrary web script or HTML through a complex interaction of IFRAME elements and WindowProxy objects. With a CVSS score of 4.3, it is a medium severity vulnerability, requiring medium attack complexity but potentially leading to information disclosure. While not on the KEV catalog, its high EPSS score and FAUCET Risk Score of 99/100 indicate significant exploitability. Metasploit modules exist for this vulnerability, and it has received notable community discussion and media coverage, suggesting active interest from threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.