First published: Thu May 22 2014(Updated: )
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript code that interacts improperly with a CollectGarbage function call on a CMarkup object allocated by the CMarkup::CreateInitialMarkup function.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =6 | |
Internet Explorer | =7 | |
Internet Explorer | =8 | |
Internet Explorer | =9 | |
Internet Explorer | =10 | |
Internet Explorer | =11 | |
=6 | ||
=7 | ||
=8 | ||
=9 | ||
=10 | ||
=11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1770 is considered a critical vulnerability due to its potential for remote code execution.
To fix CVE-2014-1770, it is recommended to apply the latest security updates provided by Microsoft for Internet Explorer.
CVE-2014-1770 affects Microsoft Internet Explorer versions 6 through 11.
CVE-2014-1770 enables attackers to execute arbitrary code on affected systems via crafted JavaScript.
Yes, CVE-2014-1770 can be exploited through malicious web pages, potentially without user interaction if users are tricked into visiting them.