PT-2014-1076 · Microsoft · Internet Explorer
Published
2014-04-27
·
Updated
2025-05-29
·
CVE-2014-1776
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 6 through 11
Description
The issue is a use-after-free vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service via vectors related to the
CMarkup::IsConnectedToPrimaryMarkup function. This vulnerability was exploited in the wild in April 2014. It is noted that the issue was originally associated with VGX.DLL, but Microsoft clarified that VGX.DLL does not contain the vulnerable code and that disabling VGX.DLL is an exploit-specific workaround.Recommendations
For Microsoft Internet Explorer versions 6 through 11, consider disabling the
CMarkup::IsConnectedToPrimaryMarkup function as a temporary workaround until a patch is available. Additionally, disabling VGX.DLL can provide an immediate and effective workaround to help block known attacks.Exploit
Fix
RCE
DoS
Use After Free
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer