CVE-2014-4082: Buffer Overflow
Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this vulnerability?
Systems running Microsoft Internet Explorer versions 6 through 10 are affected. The issue is remotely reachable over the network and does not require attacker authentication.
What does an attacker need to do to exploit it?
An attacker needs to induce a user to visit a crafted web site. Successful exploitation can result in arbitrary code execution or a denial of service through memory corruption.
What can be done if patching cannot be completed immediately?
The provided data identifies the affected browser versions but does not specify configuration-based mitigations or workarounds. Until the applicable Microsoft security update is deployed, avoiding use of the affected Internet Explorer versions reduces exposure to crafted websites.