CVE-2014-1776

Description

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014. NOTE: this issue originally emphasized VGX.DLL, but Microsoft clarified that VGX.DLL does not contain the vulnerable code leveraged in this exploit. Disabling VGX.DLL is an exploit-specific workaround that provides an immediate, effective workaround to help block known attacks.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
81.844

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Internet Explorer for Windows XP (KB2964358)Windows
Security Update for Internet Explorer for Windows Server 2003 (KB2964358)Windows
Security Update for Internet Explorer for Windows XP x64 Edition (KB2964358)Windows
Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2964358)Windows
Security Update for Internet Explorer 7 for Windows XP (KB2964358)Windows
Security Update for Internet Explorer 7 for Windows Server 2003 (KB2964358)Windows
Security Update for Internet Explorer 7 in Windows Vista (KB2964358)Windows
Security Update for Internet Explorer 7 in Windows Server 2008 (KB2964358)Windows
Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2964358)Windows
Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2964358)Windows
Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2964358)Windows
Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2964358)Windows
Security Update for Internet Explorer 8 for Windows XP (KB2964358)Windows
Security Update for Internet Explorer 8 for Windows Server 2003 (KB2964358)Windows
Security Update for Internet Explorer 8 in Windows Vista (KB2964358)Windows
Security Update for Internet Explorer 8 in Windows Server 2008 (KB2964358)Windows
Security Update for Internet Explorer 8 in Windows 7 (KB2964358)Windows
Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2964358)Windows
Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2964358)Windows
Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2964358)Windows
Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2964358)Windows
Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2964358)Windows
Security Update for Internet Explorer 9 in Windows Vista (KB2964358)Windows
Security Update for Internet Explorer 9 in Windows Server 2008 (KB2964358)Windows
Security Update for Internet Explorer 9 in Windows 7 (KB2964358)Windows
Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2964358)Windows
Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2964358)Windows
Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2964358)Windows
Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2964358)Windows
Security Update for Internet Explorer 10 for Windows 7 SP1 (KB2964358)Windows
Security Update for Internet Explorer 10 for Windows 8 (KB2964358)Windows
Security Update for Internet Explorer 10 for Windows 7 SP1 for x64-based systems (KB2964358)Windows
Security Update for Internet Explorer 10 for Server 2008 R2 SP1 (KB2964358)Windows
Security Update for Internet Explorer 10 for Windows 8 for x64-based systems (KB2964358)Windows
Security Update for Internet Explorer 10 for Windows Server 2012 (KB2964358)Windows
Security Update for Internet Explorer 11 for Windows 7 SP1 (KB2964358)Windows
Security Update for Internet Explorer 11 for Windows 8.1 (KB2964358)Windows
Security Update for Internet Explorer 11 for Windows 7 SP1 for x64-based systems (KB2964358)Windows
Security Update for Internet Explorer 11 for Server 2008 R2 SP1 (KB2964358)Windows
Security Update for Internet Explorer 11 for Windows 8.1 for x64-based systems (KB2964358)Windows
Security Update for Internet Explorer 11 for Windows Server 2012 R2 (KB2964358)Windows
Security Update for Internet Explorer 11 for Windows 7 SP1 (KB2964444)Windows
Security Update for Internet Explorer 11 for Windows 7 SP1 for x64-based systems (KB2964444)Windows
Security Update for Internet Explorer 11 for Server 2008 R2 SP1 (KB2964444)Windows
Security Update for Internet Explorer 11 for Windows 8.1 for x64-based systems (KB2964444)Windows
Security Update for Internet Explorer 11 for Windows Server 2012 R2 (KB2964444)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-15374Security Update for Internet Explorer for Windows XP (KB2964358)
PATCH-15375Security Update for Internet Explorer for Windows Server 2003 (KB2964358)
PATCH-15376Security Update for Internet Explorer for Windows XP x64 Edition (KB2964358)
PATCH-15377Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2964358)
PATCH-15378Security Update for Internet Explorer 7 for Windows XP (KB2964358)
PATCH-15379Security Update for Internet Explorer 7 for Windows Server 2003 (KB2964358)
PATCH-15380Security Update for Internet Explorer 7 in Windows Vista (KB2964358)
PATCH-15381Security Update for Internet Explorer 7 in Windows Server 2008 (KB2964358)
PATCH-15382Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2964358)
PATCH-15383Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2964358)
PATCH-15384Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2964358)
PATCH-15385Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2964358)
PATCH-15386Security Update for Internet Explorer 8 for Windows XP (KB2964358)
PATCH-15387Security Update for Internet Explorer 8 for Windows Server 2003 (KB2964358)
PATCH-15388Security Update for Internet Explorer 8 in Windows Vista (KB2964358)
PATCH-15389Security Update for Internet Explorer 8 in Windows Server 2008 (KB2964358)
PATCH-15390Security Update for Internet Explorer 8 in Windows 7 (KB2964358)
PATCH-15391Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2964358)
PATCH-15393Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2964358)
PATCH-15394Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2964358)
PATCH-15395Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2964358)
PATCH-15397Security Update for Internet Explorer 9 in Windows Vista (KB2964358)
PATCH-15398Security Update for Internet Explorer 9 in Windows Server 2008 (KB2964358)
PATCH-15399Security Update for Internet Explorer 9 in Windows 7 (KB2964358)
PATCH-15400Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2964358)
PATCH-15401Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2964358)
PATCH-15402Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2964358)
PATCH-15404Security Update for Internet Explorer 10 for Windows 7 SP1 (KB2964358)
PATCH-15405Security Update for Internet Explorer 10 for Windows 8 (KB2964358)
PATCH-15406Security Update for Internet Explorer 10 for Windows 7 SP1 for x64-based systems (KB2964358)
PATCH-15407 Security Update for Internet Explorer 10 for Server 2008 R2 SP1 (KB2964358)
PATCH-15408Security Update for Internet Explorer 10 for Windows 8 for x64-based systems (KB2964358)
PATCH-15409Security Update for Internet Explorer 10 for Windows Server 2012 (KB2964358)
PATCH-15411Security Update for Internet Explorer 11 for Windows 8.1 (KB2964358)
PATCH-15412Security Update for Internet Explorer 11 for Windows 7 SP1 for x64-based systems (KB2964358)
PATCH-15413Security Update for Internet Explorer 11 for Server 2008 R2 SP1 (KB2964358)
PATCH-15414Security Update for Internet Explorer 11 for Windows 8.1 for x64-based systems (KB2964358)
PATCH-15415Security Update for Internet Explorer 11 for Windows Server 2012 R2 (KB2964358)
PATCH-15418Security Update for Internet Explorer 11 for Windows 7 SP1 for x64-based systems (KB2964444)
PATCH-15419Security Update for Internet Explorer 11 for Server 2008 R2 SP1 (KB2964444)
PATCH-15420Security Update for Internet Explorer 11 for Windows 8.1 for x64-based systems (KB2964444)
PATCH-15421Security Update for Internet Explorer 11 for Windows Server 2012 R2 (KB2964444)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234