CVE-2014-0275: Buffer Overflow
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0285 and CVE-2014-0286.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Any user running Internet Explorer versions 6 through 11 is exposed if they visit an attacker-controlled or crafted website. The issue can be exploited remotely and does not require authentication.
What does an attacker need to do to exploit it?
An attacker needs to persuade or cause a victim to load a crafted website. Successful exploitation can execute arbitrary code or cause a denial of service through memory corruption.
What should be done if affected systems are identified?
The supplied information does not identify a workaround, mitigation, or fixed version. Prioritize applying the relevant Microsoft security update for the Internet Explorer version in use.