CVE-2015-6140 is a vulnerability of currently unknown severity. Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6142, CVE-2015-6143, CVE-2015-6153, CVE-2015-6158, CVE-2015-6159, and CVE-2015-6160. EPSS estimates a 16.81% chance of exploitation in the next 30 days.

## Description

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6142, CVE-2015-6143, CVE-2015-6153, CVE-2015-6158, CVE-2015-6159, and CVE-2015-6160.

## Metrics

EPSS Probability 16.81%  
96.6th percentile  
Probability of exploitation in the next 30 days. [Learn more](https://www.first.org/epss/)

## Weakness Enumeration

- [CWE-119](https://cwe.mitre.org/data/definitions/119.html)

## Affected Software

| Vendor   | Product               | Versions      |
|----------|----------------------|---------------|
| Microsoft| Edge                 | All versions  |
| Microsoft| Internet Explorer     | 11            |

## References

- [https://www.securitytracker.com/id/1034315](https://www.securitytracker.com/id/1034315)  
- [https://www.securitytracker.com/id/1034316](https://www.securitytracker.com/id/1034316)  
- [https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-124](https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-124)  
- [https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-125](https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-125)

## Timeline

Published Dec 9, 2015  
Last Modified Jun 17, 2026  
Status Modified

## Frequently Asked Questions

**What is CVE-2015-6140?**  
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6142, CVE-2015-6143, CVE-2015-6153, CVE-2015-6158, CVE-2015-6159, and CVE-2015-6160.

**How severe is CVE-2015-6140?**  
Severity scoring for CVE-2015-6140 is pending analysis. The EPSS model estimates a 16.81% probability of exploitation in the next 30 days.

**How do I fix CVE-2015-6140?**  
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected.
