CVE-2014-4096 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft Internet Explorer

Severity
9.3CRITICALNVD
EPSS
15.8%
top 5.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 10
Latest updateMay 14

Description

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4087, CVE-2014-4095, and CVE-2014-4101.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

4
GHSA
GHSA-3gq8-c4x9-x9rh: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si↗2022-05-14
â–¶
GHSA
GHSA-v53v-93hv-wcjv: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si↗2022-05-14
â–¶
GHSA
GHSA-whxp-g4qm-8ppv: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si↗2022-05-14
â–¶
GHSA
GHSA-f749-7f34-9fpm: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web si↗2022-05-14
â–¶

💥Exploits & PoCs

3
Exploit-DB
K7 Computing (Multiple Products) - Arbitrary Write Privilege Escalation↗2015-02-04
â–¶
Exploit-DB
Trend Micro 8.0.1133 (Multiple Products) - Local Privilege Escalation↗2015-01-31
â–¶
Exploit-DB
ActualAnalyzer - 'ant' Cookie Command Execution (Metasploit)↗2014-12-16
â–¶

💬Community

2
Bugzilla
CVE-2014-3537 cups: insufficient checking leads to privilege escalation↗2014-07-02
â–¶
Bugzilla
CVE-2014-3209 ldns: ldns-keygen generates keys with world readable permissions↗2014-05-03
â–¶
CVE-2014-4096 — Microsoft vulnerability | cvebase