Microsoft Internet Explorer CVE-2014-0322 Use-After-Free Remote Code Execution Vulnerability
BID:65551
Info
Microsoft Internet Explorer CVE-2014-0322 Use-After-Free Remote Code Execution Vulnerability
| Bugtraq ID: | 65551 |
| Class: | Unknown |
| CVE: |
CVE-2014-0322 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2014 12:00AM |
| Updated: | Mar 19 2015 09:10AM |
| Credit: | FireEye |
| Vulnerable: |
Microsoft Internet Explorer 9 Avaya Messaging Application Server 5.2 Avaya Meeting Exchange - Webportal 0 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 Avaya Aura Conferencing 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer CVE-2014-0322 Use-After-Free Remote Code Execution Vulnerability
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial-of-service conditions.
Microsoft Internet Explorer 9 and 10 are affected.
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial-of-service conditions.
Microsoft Internet Explorer 9 and 10 are affected.
Exploit / POC
Microsoft Internet Explorer CVE-2014-0322 Use-After-Free Remote Code Execution Vulnerability
Reports indicate that this issue is being exploited in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following example exploit is available:
Reports indicate that this issue is being exploited in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following example exploit is available:
Solution / Fix
Microsoft Internet Explorer CVE-2014-0322 Use-After-Free Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Microsoft Internet Explorer 10
Microsoft Internet Explorer 9
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Microsoft Internet Explorer 10
-
Microsoft Cumulative Security Update for Internet Explorer 10 in Windows 7 (KB2925418)
http://www.microsoft.com/downloads/details.aspx?familyid=1cd5d849-dc7a -44a7-b9a8-004a7c64a531 -
Microsoft Cumulative Security Update for Internet Explorer 10 in Windows 7 x64 Edition (KB2925418)
http://www.microsoft.com/downloads/details.aspx?familyid=e48eb753-c0bc -4486-9674-ccb5e7335a2a -
Microsoft Cumulative Security Update for Internet Explorer 10 in Windows 8 (KB2925418)
http://www.microsoft.com/downloads/details.aspx?familyid=cca3faa3-8f7e -4936-a765-1042e8286778 -
Microsoft Cumulative Security Update for Internet Explorer 10 in Windows 8 x64 Edition (KB2925418)
http://www.microsoft.com/downloads/details.aspx?familyid=cea044b3-2aa1 -4bd0-8354-81a3b6599dc2 -
Microsoft Cumulative Security Update for Internet Explorer 10 in Windows Server 2008 R2 x64 Edition (KB2925418
http://www.microsoft.com/downloads/details.aspx?familyid=2eacd698-6a21 -40ac-98c9-1b5f6dfe4d21 -
Microsoft Cumulative Security Update for Internet Explorer 10 in Windows Server 2012 x64 Edition (KB2925418)
http://www.microsoft.com/downloads/details.aspx?familyid=0813ff8e-9b80 -4a80-bcf5-f39ec67ff0c6
Microsoft Internet Explorer 9
-
Microsoft Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2925418)
http://www.microsoft.com/downloads/details.aspx?familyid=188782d5-743b -48d6-bfd5-e3d9deb20506 -
Microsoft Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2925418)
http://www.microsoft.com/downloads/details.aspx?familyid=6f29116a-13f3 -45b3-8aea-18a34419b852 -
Microsoft Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 (KB2925418)
http://www.microsoft.com/downloads/details.aspx?familyid=e6e598ce-0c4c -4d77-b3a6-4c16c4f7dba0 -
Microsoft Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2925418)
http://www.microsoft.com/downloads/details.aspx?familyid=3b6391d4-334b -4e71-8edc-ad5170506cee -
Microsoft Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2925418)
http://www.microsoft.com/downloads/details.aspx?familyid=c10fbc49-f6a7 -45bd-91cc-22ed4fe88dcd -
Microsoft Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2925418)
http://www.microsoft.com/downloads/details.aspx?familyid=8966b18a-00b5 -49c2-8fac-4a1f86bcf173 -
Microsoft Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2925418)
http://www.microsoft.com/downloads/details.aspx?familyid=b1bcde1e-2908 -45ca-b3b1-37598cc024fb
References
Microsoft Internet Explorer CVE-2014-0322 Use-After-Free Remote Code Execution Vulnerability
References:
References:
- Microsoft Internet Explorer Homepage (Microsoft)
- Operation SnowMan: DeputyDog Actor Compromises US Veterans of Foreign Wars Websi (FireEye)
- Potential Internet Explorer 10 Zero-day Vulnerability (Symantec)
- Microsoft Security Bulletin MS14-012 (Microsoft)
- MS14-012 Cumulative Security Update for Internet Explorer (2925418) (Avaya)
- MS14-012 Cumulative Security Update for Internet Explorer (2925418) (Avaya)
- VU#732479 Internet Explorer CMarkup use-after-free vulnerability (CERT)
- Vulnerability in Internet Explorer Could Allow Remote Code Execution (Microsoft)