(MS15-066) Vulnerability in VBScript Scripting Engine Could Allow Remote Code Execution (3072604)

  Severity: CRITICAL
  CVE Identifier: CVE-2015-2372
  Advisory Date: AUG 14, 2015

  DESCRIPTION

This security update resolves a vulnerability in the Windows VBScript scripting engine in Windows. When exploited, attackers can execute code remotely on the vulnerable system. Users with administrator rights that are currently logged on in a vulnerable system are most affected by attacks leveraging this vulnerability.

  SOLUTION

  AFFECTED SOFTWARE AND VERSION

  • VBScript 5.6 (Internet Explorer 6)
  • VBScript 5.7 (Internet Explorer 7)
  • VBScript 5.8 (Internet Explorer 8)