CVE-2015-2425 is a critical memory corruption vulnerability in Microsoft Internet Explorer 11, affecting various Windows operating systems including Windows 7, 8.1, and Server versions. With a CVSS score of 8.8 (High), it allows remote attackers to execute arbitrary code or cause a denial of service through a crafted website, requiring user interaction. This vulnerability has been actively exploited in the wild, as indicated by its presence in the KEV catalog and high EPSS score, though no public exploit code is readily available. Despite its age, it garnered significant community discussion and media coverage at the time of its discovery.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.