Описание
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014. NOTE: this issue originally emphasized VGX.DLL, but Microsoft clarified that "VGX.DLL does not contain the vulnerable code leveraged in this exploit. Disabling VGX.DLL is an exploit-specific workaround that provides an immediate, effective workaround to help block known attacks."
Ссылки
- Broken LinkMitigation
- Broken Link
- Broken LinkThird Party AdvisoryVDB Entry
- Broken Link
- MitigationThird Party AdvisoryUS Government Resource
- Broken Link
- Broken LinkThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- PatchVendor Advisory
- MitigationPatchVendor Advisory
- Broken LinkMitigation
- Broken Link
- Broken LinkThird Party AdvisoryVDB Entry
- Broken Link
- MitigationThird Party AdvisoryUS Government Resource
- Broken Link
- Broken LinkThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- PatchVendor Advisory
- MitigationPatchVendor Advisory
Уязвимые конфигурации
Одновременно
Одно из
Одновременно
Одно из
Одновременно
Одно из
Одновременно
Одно из
Одновременно
Одно из
Одновременно
Одно из
EPSS
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
Связанные уязвимости
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014. NOTE: this issue originally emphasized VGX.DLL, but Microsoft clarified that "VGX.DLL does not contain the vulnerable code leveraged in this exploit. Disabling VGX.DLL is an exploit-specific workaround that provides an immediate, effective workaround to help block known attacks."
Уязвимость браузера Internet Explorer, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
EPSS
9.8 Critical
CVSS3
10 Critical
CVSS2