CVE-2014-4140: Medium severity Microsoft Internet Explorer vulnerability
Published Oct 15, 2014
·Updated
Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
Affected Software
4 affected components
Microsoft Internet Explorer=8
Microsoft Internet Explorer=9
Microsoft Internet Explorer=10
Microsoft Internet Explorer=11
Event History
Oct 15, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4140?
CVE-2014-4140 has a medium severity rating, impacting the security of Internet Explorer due to ASLR bypass.
2
How do I fix CVE-2014-4140?
To mitigate CVE-2014-4140, you should apply the latest security patches provided by Microsoft for Internet Explorer.
3
Which versions of Internet Explorer are affected by CVE-2014-4140?
CVE-2014-4140 affects Internet Explorer versions 8, 9, 10, and 11.
4
Can CVE-2014-4140 be exploited remotely?
Yes, CVE-2014-4140 allows remote attackers to exploit the vulnerability via a crafted website.
5
What type of vulnerability is CVE-2014-4140?
CVE-2014-4140 is classified as an ASLR bypass vulnerability in Microsoft Internet Explorer.