PT-2014-1062 · Microsoft · Internet Explorer

Abdulaziz Hariri

+2

·

Published

2014-06-10

·

Updated

2018-10-12

·

CVE-2014-2776

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Internet Explorer (affected versions not specified)
Description The issue is caused by an error in the Js::PathTypeHandlerBase::SetProperty function due to improper indexing when certain arguments are input, allowing an attacker to execute arbitrary code or cause a denial of service using a specially crafted website. This vulnerability could corrupt memory, enabling an attacker to execute arbitrary code in the context of the current user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2014-00144
CVE-2014-2776
ZDI-14-188

Affected Products

Internet Explorer