CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2014-1776

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score52.8630%
EPSS Percentile85.61th
Published2014年4月27日
Last Modified2026年4月21日

Vulnerability Description

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014. NOTE: this issue originally emphasized VGX.DLL, but Microsoft clarified that "VGX.DLL does not contain the vulnerable code leveraged in this exploit. Disabling VGX.DLL is an exploit-specific workaround that provides an immediate, effective workaround to help block known attacks."

Affected Platforms (CPE)

📦
Microsoft

Internet Explorer

= 6
📦
Microsoft

Internet Explorer

= 7
📦
Microsoft

Internet Explorer

= 8
📦
Microsoft

Internet Explorer

= 9
📦
Microsoft

Internet Explorer

= 10
📦
Microsoft

Internet Explorer

= 11

References & Advisories

相關漏洞威脅