Microsoft Internet Explorer CShadow Direction Integer Overflow

Strike ID:
E15-31001
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
84
Year:
2015

Description

This strike exploits an Integer Overflow vulnerability in Internet Explorer. The vulnerability is due to the failure of the CShadow::put_Direction function to sanitize user-supplied input. An attacker could exploit this vulnerability by enticing a user to view a malicious web page, executing arbitrary code on the victim machine.

CVE

References

Bid