| Vulnerability Name: | CVE-2014-1770 (CCN-92807) | ||||||||
| Assigned: | 2014-05-22 | ||||||||
| Published: | 2014-05-22 | ||||||||
| Updated: | 2018-10-12 | ||||||||
| Summary: | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript code that interacts improperly with a CollectGarbage function call on a CMarkup object allocated by the CMarkup::CreateInitialMarkup function. | ||||||||
| CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-399 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2014-1770 Source: CCN Type: Microsoft Security Bulletin MS14-035 Cumulative Security Update for Internet Explorer (2969262) Source: CCN Type: Microsoft Security Bulletin MS14-037 Cumulative Security Update for Internet Explorer (2975687) Source: CCN Type: Microsoft Security Bulletin MS14-051 Cumulative Security Update for Internet Explorer (2976627) Source: CCN Type: Microsoft Web site Internet Explorer Source: CERT-VN Type: Third Party Advisory, US Government Resource VU#239151 Source: BID Type: VDB Entry 67544 Source: CCN Type: BID-67544 Microsoft Internet Explorer CVE-2014-1770 Remote Code Execution Vulnerability Source: SECTRACK Type: VDB Entry 1030266 Source: MISC Type: Mitigation, VDB Entry http://zerodayinitiative.com/advisories/ZDI-14-140/ Source: MS Type: UNKNOWN MS14-035 Source: XF Type: UNKNOWN ms-ie-cve20141770-code-exec(92807) Source: MISC Type: Third Party Advisory https://www.corelan.be/index.php/2014/05/22/on-cve-2014-1770-zdi-14-140-internet-explorer-8-0day/ Source: CCN Type: ZDI-14-140 (0Day) Microsoft Internet Explorer CMarkup Use-After-Free Remote Code Execution Vulnerability | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| Oval Definitions | |||||||||
| |||||||||
| BACK | |||||||||