CVE-2014-2798: Buffer Overflow
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2789, CVE-2014-2795, and CVE-2014-2804.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems using Microsoft Internet Explorer versions 8 through 11 are affected. Exploitation can be initiated remotely through a crafted web site.
What access does an attacker need to exploit it?
The vulnerability is remotely reachable and does not require attacker authentication. The supplied severity vector indicates network access with no authentication required, although exploitation has medium complexity.
What is the potential impact of successful exploitation?
A successful attacker may execute arbitrary code or cause a denial of service through memory corruption. The supplied vector rates confidentiality, integrity, and availability impact as complete.