CVE-2014-4081: Buffer Overflow
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2799, CVE-2014-4059, CVE-2014-4065, CVE-2014-4079, CVE-2014-4083, CVE-2014-4085, CVE-2014-4088, CVE-2014-4090, CVE-2014-4094, CVE-2014-4097, CVE-2014-4100, CVE-2014-4103, CVE-2014-4104, CVE-2014-4105, CVE-2014-4106, CVE-2014-4107, CVE-2014-4108, CVE-2014-4109, CVE-2014-4110, and CVE-2014-4111.
Affected Software
Event History
Frequently Asked Questions
Which Internet Explorer installations are affected?
Systems running Microsoft Internet Explorer versions 6 through 11 are affected. The issue can lead to arbitrary code execution or denial of service through memory corruption.
What does an attacker need to do to exploit this vulnerability?
An attacker can exploit the issue remotely by using a crafted web site. The supplied vector does not indicate that authentication is required.
What is the potential impact of successful exploitation?
The provided data identifies this issue as a buffer overflow and assigns a critical severity score of 9.3, with impacts to confidentiality, integrity, and availability.