MS15-124: Cumulative Security Update for Internet Explorer (CVE-2015-6161) (3125869)

low Nessus Plugin ID 134204

Synopsis

The remote host has a web browser installed that is affected by multiple vulnerabilities.

Description

The version of Internet Explorer installed on the remote host is missing Cumulative Security Update 3125869 and/or a Registry key to prevent the host against CVE-2015-6161. It is, therefore, affected by Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka 'Microsoft Browser ASLR Bypass'.
An unauthenticated, remote attacker can exploit this issue by convincing a user to visit a specially craftedwebsite, resulting in the execution of arbitrary code in the context of the current user.

A specific Fix to Run from Microsoft or a registry value must be added to enable the fix for CVE-2015-6161.

Solution

Microsoft has released a set of patches for Windows Vista, 2008, 7, 2008 R2, 8, RT, 2012, 8.1, RT 8.1, 2012 R2, and 10.

Refer to KB3125869 for additional information.

See Also

http://www.nessus.org/u?f205555e

http://www.nessus.org/u?43c16242

Plugin Details

Severity: Low

ID: 134204

File Name: smb_nt_ms15_nov_3116869_CVE_2015-6161.nasl

Version: 1.3

Type: local

Agent: windows

Published: 3/2/2020

Updated: 6/9/2022

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2015-6161

CVSS v3

Risk Factor: Low

Base Score: 3.1

Temporal Score: 3

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:microsoft:windows, cpe:/a:microsoft:ie

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 12/8/2015

Vulnerability Publication Date: 12/8/2015

Reference Information

CVE: CVE-2015-6161

MSFT: MS15-124

MSKB: 3125869