CVE-2014-4092: Buffer Overflow
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4098.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Users of Internet Explorer 8 through 11 are exposed if they visit an attacker-controlled or crafted website. The attack can be delivered remotely and requires no authentication.
What does an attacker need to exploit this issue?
An attacker needs to persuade or cause a victim to load a crafted web page in a vulnerable Internet Explorer version. Successful exploitation can lead to arbitrary code execution or a denial of service through memory corruption.
Is a particular Internet Explorer configuration required?
The supplied information identifies Internet Explorer 8 through 11 as affected but does not describe any configuration prerequisite or non-default setting. Organizations should treat systems running those versions as potentially affected when users can browse the web.