Executive brief
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain elevated privileges via a specially crafted website. This vulnerability is distinct from CVE-2014-4124 and has been observed being exploited in the wild.
Affected products
- Microsoft Internet Explorer 7 through 11
Timeline
- 2014-10-14: disclosed: Initial disclosure and reported exploitation in the wild.
- 2014-10-14: patched: Microsoft released security bulletin MS14-056.
- 2014-10-01: exploited: Exploited in the wild in October 2014.
- 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.