CVE-2014-4128: Input Validation
Published Oct 15, 2014
·Updated
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
Affected Software
6 affected components
Microsoft Internet Explorer=6
Microsoft Internet Explorer=7
Microsoft Internet Explorer=8
Microsoft Internet Explorer=9
Microsoft Internet Explorer=10
Microsoft Internet Explorer=11
Event History
Oct 15, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4128?
CVE-2014-4128 has a critical severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2014-4128?
To fix CVE-2014-4128, update Microsoft Internet Explorer to the latest version or apply the relevant security patches.
3
What versions of Internet Explorer are affected by CVE-2014-4128?
CVE-2014-4128 affects Microsoft Internet Explorer versions 6 through 11.
4
What type of attacks can exploit CVE-2014-4128?
CVE-2014-4128 can be exploited by attackers to execute arbitrary code or cause a denial of service.
5
Is there a workaround for CVE-2014-4128?
There are no effective workarounds for CVE-2014-4128; updating the browser is recommended.