CVE-2014-4129: Input Validation
Published Oct 15, 2014
·Updated
Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
Affected Software
1 affected component
Microsoft Internet Explorer=8
Event History
Oct 15, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
Who is exposed to exploitation?
Users of Internet Explorer 8 are exposed if they visit an attacker-controlled or crafted website. Exploitation does not require authentication and can result in arbitrary code execution or a denial of service through memory corruption.
2
What does an attacker need to do to trigger the vulnerability?
An attacker needs to persuade or otherwise cause a user to access a crafted website. The supplied information does not identify any additional prerequisites or configuration changes required for exploitation.