Junglewise Threat Intelligence

CVE-2014-0322: Microsoft Internet Explorer Use-After-Free Vulnerability

CVE-2014-0322 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-05-04

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

A use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code. The flaw is triggered via crafted JavaScript code involving CMarkup and the onpropertychange attribute of a script element.

Affected products

  • Microsoft Internet Explorer 9 and 10

Timeline

  • 2014-01: exploited: Exploited in the wild in January and February 2014.
  • 2014-02-13: disclosed: Public blog post regarding 0-day exploit.
  • 2022-05-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats