CVE-2014-1776
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 27, 2014
Updated: Dec 19, 2024
CWE ID 416
Summary
CVE-2014-1776 is a use-after-free vulnerability affecting Microsoft Internet Explorer 6 through 11. This issue allows remote attackers to execute arbitrary code or cause a denial of service by exploiting a memory corruption vulnerability in the CMarkup::IsConnectedToPrimaryMarkup function. The vulnerability was actively exploited in the wild in April 2014, but it is important to note that VGX.DLL is not the source of the vulnerable code, and disabling it is an exploit-specific workaround.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Internet Explorer
Affected Vendors
- Microsoft