CVE-2014-2801: Buffer Overflow
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems running Microsoft Internet Explorer 10 or 11 are affected. Exploitation can be initiated remotely through a crafted website, so users who browse to attacker-controlled content are exposed.
Does exploitation require authentication or prior access?
No authentication is required. The supplied vector indicates network-based exploitation with no required privileges, although the attack complexity is rated medium.
What can a successful attacker do?
A successful attacker may execute arbitrary code or cause a denial of service through memory corruption. The vulnerability is rated critical with impacts to confidentiality, integrity, and availability.