CVE-2014-1766: Buffer Overflow
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at CanSecWest 2014. NOTE: the original disclosure referred to triggering a kernel bug with the Internet Explorer exploit payload, but this ID is not for a kernel vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1766?
CVE-2014-1766 is considered critical due to its potential for remote code execution and memory corruption.
How do I fix CVE-2014-1766?
To mitigate CVE-2014-1766, users should update their Internet Explorer to the latest available version provided by Microsoft.
Which versions of Internet Explorer are affected by CVE-2014-1766?
CVE-2014-1766 affects Internet Explorer versions 9, 10, and 11.
What types of attacks can CVE-2014-1766 facilitate?
CVE-2014-1766 can facilitate arbitrary code execution or cause a denial of service via a crafted website.
Who discovered CVE-2014-1766?
CVE-2014-1766 was demonstrated by security researchers Sebastian Apelt and Andreas Schmidt during the Pwn2Own competition in 2014.