Microsoft Internet Explorer CVE-2014-1763 Use-After-Free Remote Code Execution Vulnerability
BID:66200
Info
Microsoft Internet Explorer CVE-2014-1763 Use-After-Free Remote Code Execution Vulnerability
| Bugtraq ID: | 66200 |
| Class: | Design Error |
| CVE: |
CVE-2014-1763 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 13 2014 12:00AM |
| Updated: | Jul 28 2014 12:19AM |
| Credit: | VUPEN Security (Pwn2Own 2014), working with HP's Zero Day Initiative |
| Vulnerable: |
Microsoft Internet Explorer 9 Avaya Messaging Application Server 5.2 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer CVE-2014-1763 Use-After-Free Remote Code Execution Vulnerability
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial-of-service conditions.
Note: The issue described by CVE-2014-1764 has been moved to BID 67295 (Microsoft Internet Explorer CVE-2014-1764 Remote Code Execution Vulnerability) for better documentation.
Internet Explorer 9,10 and 11 are vulnerable.
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial-of-service conditions.
Note: The issue described by CVE-2014-1764 has been moved to BID 67295 (Microsoft Internet Explorer CVE-2014-1764 Remote Code Execution Vulnerability) for better documentation.
Internet Explorer 9,10 and 11 are vulnerable.
Exploit / POC
Microsoft Internet Explorer CVE-2014-1763 Use-After-Free Remote Code Execution Vulnerability
Exploitation of this issue was demonstrated at the Pwn2Own contest, but the exploit is not publicly available.
Exploitation of this issue was demonstrated at the Pwn2Own contest, but the exploit is not publicly available.
Solution / Fix
Microsoft Internet Explorer CVE-2014-1763 Use-After-Free Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Microsoft Internet Explorer CVE-2014-1763 Use-After-Free Remote Code Execution Vulnerability
References:
References:
- Microsoft Internet Explorer Homepage (Microsoft)