Microsoft Internet Explorer CVE-2014-0290 Memory Corruption Vulnerability
BID:65390
Info
Microsoft Internet Explorer CVE-2014-0290 Memory Corruption Vulnerability
| Bugtraq ID: | 65390 |
| Class: | Unknown |
| CVE: |
CVE-2014-0290 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2014 12:00AM |
| Updated: | Mar 19 2015 08:31AM |
| Credit: | Bo Qu of Palo Alto Networks |
| Vulnerable: |
Microsoft Internet Explorer 11 Avaya Messaging Application Server 5.2.1 Avaya Messaging Application Server 5.0.1 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5.2 Avaya Messaging Application Server 5.0 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 6.2 Avaya Meeting Exchange - Webportal 6.0 Avaya Meeting Exchange - Webportal 5.2.1 Avaya Meeting Exchange - Webportal 5.2 Avaya Meeting Exchange - Webportal 5.0.1 Avaya Meeting Exchange - Webportal 5.0 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Web Conferencing Server 6.2 Avaya Meeting Exchange - Web Conferencing Server 6.0 Avaya Meeting Exchange - Web Conferencing Server 5.2.1 Avaya Meeting Exchange - Web Conferencing Server 5.2 Avaya Meeting Exchange - Web Conferencing Server 5.0.1 Avaya Meeting Exchange - Web Conferencing Server 5.0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 6.2 Avaya Meeting Exchange - Streaming Server 6.0 Avaya Meeting Exchange - Streaming Server 5.2.1 Avaya Meeting Exchange - Streaming Server 5.2 Avaya Meeting Exchange - Streaming Server 5.0.1 Avaya Meeting Exchange - Streaming Server 5.0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 6.2 Avaya Meeting Exchange - Recording Server 6.0 Avaya Meeting Exchange - Recording Server 5.2.1 Avaya Meeting Exchange - Recording Server 5.2 Avaya Meeting Exchange - Recording Server 5.0.1 Avaya Meeting Exchange - Recording Server 5.0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 6.2 Avaya Meeting Exchange - Client Registration Server 6.0 Avaya Meeting Exchange - Client Registration Server 5.2.1 Avaya Meeting Exchange - Client Registration Server 5.2 Avaya Meeting Exchange - Client Registration Server 5.0.1 Avaya Meeting Exchange - Client Registration Server 5.0 Avaya Meeting Exchange - Client Registration Server 0 Avaya Conferencing Standard Edition 6.0.1 Avaya Conferencing Standard Edition 7.0 Avaya Conferencing Standard Edition 6.0 SP1 Avaya Conferencing Standard Edition 6.0 Avaya Communication Server 1000 Telephony Manager 4.0.1 Avaya Communication Server 1000 Telephony Manager 3.0.1 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya Communication Server 1000 Telephony Manager 0 Avaya CallPilot 5.0.1 Avaya CallPilot 4.0.1 Avaya CallPilot 5.0 Avaya CallPilot 4.0 Avaya CallPilot 0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer CVE-2014-0290 Memory Corruption Vulnerability
Microsoft Internet Explorer is prone to a memory-corruption vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial-of-service conditions.
Microsoft Internet Explorer is prone to a memory-corruption vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial-of-service conditions.
Solution / Fix
Microsoft Internet Explorer CVE-2014-0290 Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Microsoft Internet Explorer 11
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Microsoft Internet Explorer 11
-
Microsoft Cumulative Security Update for Internet Explorer 11 for Windows 8.1 (KB2909921)
http://www.microsoft.com/downloads/details.aspx?familyid=caa2e0ef-8d2e -4faf-b8ba-ca89a2e00610 -
Microsoft Cumulative Security Update for Internet Explorer 11 for Windows 8.1 for x64-based systems (KB2909921
http://www.microsoft.com/downloads/details.aspx?familyid=75980a75-3d8d -4c4d-95d7-a4d7e575c8ee -
Microsoft Cumulative Security Update for Internet Explorer 11 for Windows Server 2012 R2 (KB2909921)
http://www.microsoft.com/downloads/details.aspx?familyid=e1b0f24e-b89d -4b19-bc64-cee1df86abbd -
Microsoft Cumulative Security Update for Internet Explorer 11 in Windows 7 (KB2909921)
http://www.microsoft.com/downloads/details.aspx?familyid=5dfdd4da-4991 -40cb-bd08-890832eb72be -
Microsoft Cumulative Security Update for Internet Explorer 11 in Windows 7 x64 Edition (KB2909921)
http://www.microsoft.com/downloads/details.aspx?familyid=790f9ddd-5ba9 -4bdf-aec7-7661aed71963 -
Microsoft Cumulative Security Update for Internet Explorer 11 in Windows Server 2008 R2 x64 Edition (KB2909921
http://www.microsoft.com/downloads/details.aspx?familyid=c23cc6dd-a756 -4e5a-bd6a-0d4dbbff8748
References
Microsoft Internet Explorer CVE-2014-0290 Memory Corruption Vulnerability
References:
References:
- Microsoft Internet Explorer Homepage (Microsoft)
- MS14-010 Cumulative Security Update for Internet Explorer (2909921) (Avaya)
- Microsoft Internet Explorer CMarkup Undo execCommand Use-After-Free Remote Code (Zero Day Initiative)
- Microsoft Security Bulletin MS14-010 (Microsoft)