CVE-2014-2800: Buffer Overflow
Published Jul 8, 2014
·Updated
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2807 and CVE-2014-2809.
Affected Software
6 affected components
Microsoft Internet Explorer=6
Microsoft Internet Explorer=7
Microsoft Internet Explorer=8
Microsoft Internet Explorer=9
Microsoft Internet Explorer=10
Microsoft Internet Explorer=11
Event History
Jul 8, 2014
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
Who is exposed to this vulnerability?
Users of Microsoft Internet Explorer versions 6 through 11 are affected. Because exploitation is via a crafted website and requires no authentication, systems that browse to attacker-controlled or compromised web content are exposed.
2
What can an attacker achieve?
A remote attacker can trigger memory corruption that results in arbitrary code execution or a denial of service. The impact includes compromise of confidentiality, integrity, and availability.