PT-2014-1080 · Microsoft · Internet Explorer

Published

2014-02-11

·

Updated

2018-10-12

·

CVE-2014-0272

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Internet Explorer versions 8 through 10
Description The issue is related to a use-after-free error, which occurs due to insufficient validation of user input when CMarkup attempts to unload a file. This allows remote attackers to execute arbitrary code or cause a denial of service via a specially crafted website. The vulnerability could corrupt memory, enabling an attacker to execute arbitrary code in the context of the current user.
Recommendations For Internet Explorer versions 8 through 10, update to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to potentially malicious websites to minimize the risk of exploitation.

Fix

RCE

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2014-00162
CVE-2014-0272

Affected Products

Internet Explorer