Junglewise Threat Intelligence

CVE-2014-4123: Microsoft Internet Explorer Privilege Escalation Vulnerability

CVE-2014-4123 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-05-25

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

Microsoft Internet Explorer 7 through 11 allows remote attackers to gain elevated privileges via a specially crafted website. This vulnerability is distinct from CVE-2014-4124 and has been observed being exploited in the wild.

Affected products

  • Microsoft Internet Explorer 7 through 11

Timeline

  • 2014-10-14: disclosed: Initial disclosure and reported exploitation in the wild.
  • 2014-10-14: patched: Microsoft released security bulletin MS14-056.
  • 2014-10-01: exploited: Exploited in the wild in October 2014.
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats