CyberSec.Space Logo
Back to CVE Browser

CVE-2014-1776

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score52.8630%
EPSS Percentile85.61th
PublishedApr 27, 2014
Last ModifiedApr 21, 2026

Vulnerability Description

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014. NOTE: this issue originally emphasized VGX.DLL, but Microsoft clarified that "VGX.DLL does not contain the vulnerable code leveraged in this exploit. Disabling VGX.DLL is an exploit-specific workaround that provides an immediate, effective workaround to help block known attacks."

Affected Platforms (CPE)

πŸ“¦
Microsoft

Internet Explorer

= 6
πŸ“¦
Microsoft

Internet Explorer

= 7
πŸ“¦
Microsoft

Internet Explorer

= 8
πŸ“¦
Microsoft

Internet Explorer

= 9
πŸ“¦
Microsoft

Internet Explorer

= 10
πŸ“¦
Microsoft

Internet Explorer

= 11

References & Advisories

Related Vulnerabilities