CVE-2014-0288: Buffer Overflow
Published Feb 12, 2014
·Updated
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0270, CVE-2014-0273, and CVE-2014-0274.
Affected Software
3 affected components
Microsoft Internet Explorer=9
Microsoft Internet Explorer=10
Microsoft Internet Explorer=11
Event History
Feb 12, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·04:50 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which systems are exposed and what does an attacker need to exploit the issue?
Systems running Internet Explorer 9, 10, or 11 are exposed. Exploitation can be initiated remotely through a crafted website, with no authentication required.
2
What impact should be assumed during triage?
A successful attack can execute arbitrary code or cause a denial of service through memory corruption. The provided data does not identify any configuration prerequisite or mitigation for systems that cannot be patched immediately.