Описание
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014.
Ссылки
- Broken LinkPermissions Required
 - PatchVendor Advisory
 - Press/Media Coverage
 - ExploitThird Party AdvisoryVDB Entry
 - ExploitThird Party AdvisoryVDB Entry
 - Broken Link
 - Broken Link
 - Third Party AdvisoryUS Government Resource
 - Broken Link
 - PatchVendor Advisory
 - Broken LinkExploit
 - Broken LinkPermissions Required
 - PatchVendor Advisory
 - Press/Media Coverage
 - ExploitThird Party AdvisoryVDB Entry
 - ExploitThird Party AdvisoryVDB Entry
 - Broken Link
 - Broken Link
 - Third Party AdvisoryUS Government Resource
 - Broken Link
 
Уязвимые конфигурации
Одновременно
Одно из
Одновременно
Одно из
EPSS
8.8 High
CVSS3
9.3 Critical
CVSS2
Дефекты
Связанные уязвимости
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014.
Уязвимость браузера Internet Explorer, позволяющая злоумышленнику выполнить произвольный код
EPSS
8.8 High
CVSS3
9.3 Critical
CVSS2