EXPOSURES › CVE-2015-2425
CVE-2015-2425
HIGH ⌖ ON CISA KEV · EXPLOITEDA memory corruption flaw in Internet Explorer allowed remote attackers to execute code or cause denial-of-service.
This unpatched vulnerability was actively exploited in the wild, enabling remote code execution and denial-of-service attacks. DIB organizations must ensure legacy browsers are patched or replaced, as reliance on unpatched software violates CMMC/NIST 800-171 requirements for timely patching and vulnerability management.
Shame score — Microsoft shipped a known, actively exploited vulnerability in a widely used product without timely patching, demonstrating negligence in vulnerability management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |