PT-2014-1076 · Microsoft · Internet Explorer

Publicado

2014-04-27

·

Atualizado

2025-05-29

·

CVE-2014-1776

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 6 through 11
Description The issue is a use-after-free vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function. This vulnerability was exploited in the wild in April 2014. It is noted that the issue was originally associated with VGX.DLL, but Microsoft clarified that VGX.DLL does not contain the vulnerable code and that disabling VGX.DLL is an exploit-specific workaround.
Recommendations For Microsoft Internet Explorer versions 6 through 11, consider disabling the CMarkup::IsConnectedToPrimaryMarkup function as a temporary workaround until a patch is available. Additionally, disabling VGX.DLL can provide an immediate and effective workaround to help block known attacks.

Exploit

Correção

RCE

DoS

Use After Free

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2014-00158
CVE-2014-1776

Produtos afetados

Internet Explorer