CVE-2015-6139: Microsoft Edge

High severity, CVSS 9.3. EPSS: 15.4% chance of exploitation in the next 30 days.

Microsoft Internet Explorer 11 and Microsoft Edge mishandle content types, which allows remote attackers to execute arbitrary web script in a privileged context via a crafted web site, aka "Microsoft Browser Elevation of Privilege Vulnerability."

Affected products

  • Microsoft Edge: affected versions not specified
  • Microsoft Internet Explorer: version 11 only

Published 2015-12-09. Last modified 2026-06-17.