PT-2014-1092 · Microsoft · Internet Explorer

Jason Kratzer

·

Published

2014-03-11

·

Updated

2018-10-12

·

CVE-2014-0307

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Internet Explorer version 9
Description The issue is related to a use-after-free error when working with the TextRange object, allowing remote attackers to execute arbitrary code or cause a denial of service through memory corruption by manipulating a certain sequence of TextRange elements. This could lead to memory corruption, enabling an attacker to execute arbitrary code in the context of the current user.
Recommendations For Internet Explorer version 9, update to a newer version to mitigate the risk, as the current version is affected by the use-after-free vulnerability related to the TextRange object.

Exploit

Fix

DoS

RCE

Buffer Overflow

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2014-00174
CVE-2014-0307
ZDI-14-036

Affected Products

Internet Explorer