CVE-2014-4141: Buffer Overflow
Published Oct 15, 2014
·Updated
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
Affected Software
4 affected components
Microsoft Internet Explorer=8
Microsoft Internet Explorer=9
Microsoft Internet Explorer=10
Microsoft Internet Explorer=11
Event History
Oct 15, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
Which environments are exposed to this vulnerability?
Systems running Microsoft Internet Explorer 8, 9, 10, or 11 are affected. The issue can be triggered remotely through a crafted web site.
2
What does an attacker need to exploit this issue?
An attacker does not need authentication. They need to induce a user to visit a crafted web site, which can lead to arbitrary code execution or a denial of service through memory corruption.