Executive brief
A use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code. The flaw is triggered via crafted JavaScript code involving CMarkup and the onpropertychange attribute of a script element.
Affected products
- Microsoft Internet Explorer 9 and 10
Timeline
- 2014-01: exploited: Exploited in the wild in January and February 2014.
- 2014-02-13: disclosed: Public blog post regarding 0-day exploit.
- 2022-05-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.