CVE-2014-2786: Buffer Overflow
Published Jul 8, 2014
·Updated
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2792 and CVE-2014-2813.
Affected Software
3 affected components
Microsoft Internet Explorer=9
Microsoft Internet Explorer=10
Microsoft Internet Explorer=11
Event History
Jul 8, 2014
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
Which Internet Explorer versions are affected?
Internet Explorer 9, 10, and 11 are affected.
2
What must an attacker do to exploit this issue?
An attacker must entice or cause a target to visit a crafted web site. No authentication is required.
3
What impact could successful exploitation have?
Successful exploitation can result in arbitrary code execution or a denial of service caused by memory corruption. The vulnerability is rated critical with a CVSS vector of AV:N/AC:M/Au:N/C:C/I:C/A:C.