First published: Sun Apr 27 2014(Updated: )
Unspecified vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code with medium-integrity privileges and bypass a sandbox protection mechanism via unknown vectors, as demonstrated by ZDI during a Pwn4Fun competition at CanSecWest 2014.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =6 | |
Internet Explorer | =7 | |
Internet Explorer | =8 | |
Internet Explorer | =9 | |
Internet Explorer | =10 | |
Internet Explorer | =11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1762 has a medium severity rating due to its potential for remote code execution.
To mitigate CVE-2014-1762, ensure that you are using the latest version of Microsoft Internet Explorer and apply all recommended security updates.
CVE-2014-1762 affects Microsoft Internet Explorer versions 6 through 11.
CVE-2014-1762 can be exploited by remote attackers to execute arbitrary code and bypass sandbox protections.
While there is no formal workaround, using a different, more secure web browser is advised until a patch is applied.