CVE-2014-0322 KEV EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 85.1% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-25.
Description
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 85.12% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-416 |
| On CISA KEV | yes — remediate by 2022-05-25 |
| Public exploit | yes |
| Published | 2014-02-14 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Microsoft Internet Explorer Use-After-Free Vulnerability |
|---|---|
| Added | 2022-05-04 |
| Due | 2022-05-25 |
| Vendor / product | Microsoft / Internet Explorer |
| Ransomware use | none reported |
Affected (7)
| Vendor | Product |
|---|---|
| microsoft | internet explorer |
| microsoft | windows 7 |
| microsoft | windows 8 |
| microsoft | windows rt |
| microsoft | windows server 2008 |
| microsoft | windows server 2012 |
| microsoft | windows vista |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Internet Explorer - CMarkup Use-After-Free (MS14-012) (Metasploit) | 2014-04-16 |
| exploit-db | Microsoft Internet Explorer 10 - CMarkup Use-After-Free (MS14-012) | 2014-04-14 |
References
- http://community.websense.com/blogs/securitylabs/archive/2014/02/13/msie-0-day-exploit-cve-2014-0322-possibly-targeting-french-aerospace-organization.aspx
- http://technet.microsoft.com/security/advisory/2934088
- http://twitter.com/nanoc0re/statuses/434251658344673281
- http://www.exploit-db.com/exploits/32851
- http://www.exploit-db.com/exploits/32904
- http://www.fireeye.com/blog/technical/cyber-exploits/2014/02/new-ie-zero-day-found-in-watering-hole-attack-2.html
- http://www.fireeye.com/blog/uncategorized/2014/02/operation-snowman-deputydog-actor-compromises-us-veterans-of-foreign-wars-website.html
- http://www.kb.cert.org/vuls/id/732479
- http://www.osvdb.org/103354
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-012
- https://www.dropbox.com/s/pyxjgycmudirbqe/CVE-2014-0322.zip
- http://community.websense.com/blogs/securitylabs/archive/2014/02/13/msie-0-day-exploit-cve-2014-0322-possibly-targeting-french-aerospace-organization.aspx
- http://technet.microsoft.com/security/advisory/2934088
- http://twitter.com/nanoc0re/statuses/434251658344673281
- http://www.exploit-db.com/exploits/32851
- http://www.exploit-db.com/exploits/32904
- http://www.fireeye.com/blog/technical/cyber-exploits/2014/02/new-ie-zero-day-found-in-watering-hole-attack-2.html
- http://www.fireeye.com/blog/uncategorized/2014/02/operation-snowman-deputydog-actor-compromises-us-veterans-of-foreign-wars-website.html
- http://www.kb.cert.org/vuls/id/732479
- http://www.osvdb.org/103354
→ the Explorer · watch your stack · NVD