PoC Index

CVE-2014-1766

HIGH 9.3EPSS 33.3%

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at CanSecWest 2014. NOTE: the original disclosure referred to triggering a kernel bug with the Internet Explorer exploit payload, but this ID is not for a kernel vulnerability.

CVSS v2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
33.29% chance of exploitation in the next 30 days, 98th percentile
Published
2014-04-27
Updated
2024-08-06

ExploitDB entries (1)

References

Related