ZeroHour

CVE-2014-0322

KEVmass

Use-After-Free Remote Code Execution in Microsoft Internet Explorer

CISA: Microsoft Internet Explorer Use-After-Free Vulnerability

CVSS
EPSS
85%p100
Published
KEV added
AI analysis

CVE-2014-0322 is a use-after-free memory corruption flaw (CWE-416) in Microsoft Internet Explorer that allows remote code execution. It is triggered when the browser processes crafted web content: an attacker-controlled object is freed and then reused, corrupting memory, and in the known campaign FireEye observed it being exploited as a 0-day via a watering hole attack on websites visited by targets. A successful exploit lets an attacker execute arbitrary code with the privileges of the logged-on user, typically through nothing more than a drive-by visit to a compromised web page. Everyone browsing with the affected Internet Explorer versions was exposed, which at the time of disclosure meant on the order of hundreds of millions of desktop users given IE's dominant market share. Exploitation is confirmed in the wild - the flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2022-05-04 - though the source data notes no standalone public proof-of-concept code.

What to do: Apply Microsoft's March 2014 Internet Explorer security updates per vendor instructions, as required by the CISA KEV catalog. Inventory endpoints for legacy or unpatched IE usage, restrict browsing with IE on outdated hosts, migrate systems still using IE to a supported browser where possible, and monitor for watering-hole/drive-by compromise indicators.

Affected
Microsoft Internet Explorer
Estimated exposure
masshundreds of millions of users at the time of disclosure (IE held the majority of desktop browser share in 2014); residual exposure now limited to legacy… — Internet Explorer was the dominant desktop browser when this 0-day was disclosed in early 2014, implying exposure on the order of 10^8 installs, with remaining unpatched IE usage concentrated on legacy Windows systems.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code.

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Internet Explorer
Weakness
CWE-416

In the news