RULE(RULE ID:311993)

Rule General Information
Release Date: 2015-07-27
Rule Name: Microsoft Windows Vbscript Regular Expression Information Disclosure Vulnerability -2 (CVE-2015-1684)
Severity:
CVE ID:
Rule Protection Details
Description: VBScript.dll in the Microsoft VBScript 5.6 through 5.8 engine, as used in Internet Explorer 8 through 11 and other products, allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "VBScript ASLR Bypass."
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows
Reference: MicrosoftSecurityBulletin:MS15-043
MicrosoftSecurityBulletin:MS15-053
SecurityFocusBID:74522
SecurityTrackerID:1032282
Solutions
Microsoft has released a patch MS15-043 to eliminate the vulnerability. The patch can be downloaded at http://technet.microsoft.com/security/bulletin/MS15-043