Microsoft Internet Explorer CVE-2014-1766 Remote Code Execution Vulnerability
BID:67518
Info
Microsoft Internet Explorer CVE-2014-1766 Remote Code Execution Vulnerability
| Bugtraq ID: | 67518 |
| Class: | Design Error |
| CVE: |
CVE-2014-1766 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2014 12:00AM |
| Updated: | Mar 19 2015 08:45AM |
| Credit: | Sebastian Apelt and Andreas Schmidt |
| Vulnerable: |
Microsoft Internet Explorer 9 Avaya Messaging Application Server 5.2 Avaya Meeting Exchange - Webportal 0 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 Avaya Aura Conferencing 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer CVE-2014-1766 Remote Code Execution Vulnerability
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage.
Successfully exploiting this issue may allow attackers to execute arbitrary code in the context of the application. Failed exploit attempts will result in denial-of-service conditions.
Note: This issue was previously discussed in BID 66244 (Microsoft Internet Explorer Multiple Security Vulnerabilities) but has been given its own record to better document it.
Internet Explorer 9, 10 and 11 is vulnerable.
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage.
Successfully exploiting this issue may allow attackers to execute arbitrary code in the context of the application. Failed exploit attempts will result in denial-of-service conditions.
Note: This issue was previously discussed in BID 66244 (Microsoft Internet Explorer Multiple Security Vulnerabilities) but has been given its own record to better document it.
Internet Explorer 9, 10 and 11 is vulnerable.
References
Microsoft Internet Explorer CVE-2014-1766 Remote Code Execution Vulnerability
References:
References:
- Microsoft Windows Homepage (Microsoft)
- Pwn2Own results for Thursday (Day Two) (HP)
- (Pwn2Own) Microsoft Internet Explorer CDispNodeBase Use-After-Free Remote Code E (zero day initiative)
- Microsoft Security Bulletin MS14-035 (Microsoft)
- MS14-035 Cumulative Security Update for Internet Explorer (2969262) (Avaya)