CVE-2014-0267: Buffer Overflow
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0289 and CVE-2014-0290.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this vulnerability?
Systems running Microsoft Internet Explorer 11 are exposed when a user visits a crafted website. The vulnerability is remotely exploitable and does not require authentication.
What does an attacker need to exploit it?
An attacker needs to lure or otherwise cause a user to access a crafted website. Successful exploitation can result in arbitrary code execution or a denial of service through memory corruption.
Does the available information identify a configuration-based workaround?
The provided data identifies Internet Explorer 11 as affected, but it does not state whether any particular default configuration changes exposure or provide a mitigation for unpatched systems.