CVE-2014-1770

high

Description

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript code that interacts improperly with a CollectGarbage function call on a CMarkup object allocated by the CMarkup::CreateInitialMarkup function.

References

https://www.corelan.be/index.php/2014/05/22/on-cve-2014-1770-zdi-14-140-internet-explorer-8-0day/

https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-035

http://zerodayinitiative.com/advisories/ZDI-14-140/

http://www.securitytracker.com/id/1030266

http://www.securityfocus.com/bid/67544

http://www.kb.cert.org/vuls/id/239151

Details

Source: Mitre, NVD

Published: 2014-05-22

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High