Almost every Patch Tuesday cycle contains one bulletin that (for convenience) rolls up multiple Internet Explorer vulnerabilities into a single bulletin. February’s Patch Tuesday cumulative IE bulletin (MS15-009) included a fix for a particularly interesting vulnerability that could be used to bypass one of the key anti-exploit technologies in use today, address space layout randomization […]
Post from: Trendlabs Security Intelligence Blog – by Trend Micro
Bypassing ASLR with CVE-2015-0071: An Out-of-Bounds Read Vulnerability