E15-31001
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
84
Year:
2015
Description
This strike exploits an Integer Overflow vulnerability in Internet Explorer.
The vulnerability is due to the failure of the CShadow::put_Direction function to sanitize user-supplied input.
An attacker could exploit this vulnerability by enticing a user to view a malicious web page, executing arbitrary code on the victim machine.
CVE
References
http://www.zerodayinitiative.com/advisories/ZDI-15-019/