Junglewise Threat Intelligence

CVE-2014-1776: Microsoft Internet Explorer Memory Corruption Vulnerability

CVE-2014-1776 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-01-28

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

A use-after-free vulnerability exists in Microsoft Internet Explorer versions 6 through 11 due to improper handling of objects in memory via the CMarkup::IsConnectedToPrimaryMarkup function. Remote attackers can exploit this to execute arbitrary code or cause a denial of service in the context of the current user.

Affected products

  • Microsoft Internet Explorer 6 through 11

Timeline

  • 2014-04-01: exploited: Exploited in the wild in April 2014.
  • 2014-05-01: patched: Microsoft released security bulletin MS14-021 to address the issue.
  • 2022-01-28: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.

Related threats