Internet Explorer & Adobe Flash 0
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2014-1776 | Use-After-Free Memory Corruption RCE in Microsoft Internet Explorer CVE-2014-1776 is a use-after-free memory corruption flaw in Microsoft Internet Explorer that can be triggered when the browser processes specially crafted web content, corrupting memory in a manner an attacker controls. A remote attacker can deliver the malicious content from a site they host or inject it into a compromised/legitimate website, causing Internet Explorer to access freed memory under attacker control. Successful exploitation allows arbitrary code execution in the context of the current user, giving the attacker that user's privileges on the client machine. Any organization or user running an affected version of Internet Explorer is exposed, and the flaw has been associated with highly targeted attack activity, including the FireEye-documented zero-day exploit in the wild and the targeted Pirpi-distributed 0-day. The vulnerability was exploited in the wild as a zero-day, was addressed by Microsoft updates, and was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-01-28; no public proof-of-concept is known. Do: Apply Microsoft's Internet Explorer security updates per vendor instructions, prioritizing this as a KEV-required remediation, and verify all workstations still launching IE or legacy MSHTML-based content are patched. Reduce residual exposure by steering users away from Internet Explorer for untrusted sites and auditing intranet applications and tooling for lingering IE dependencies. Because the exact affected versions are not in the data, cross-check Microsoft's advisory to confirm your deployed IE versions are covered by the fix. | — | 88% | KEV |
| mass≈ hundreds of millions of users/endpoints (IE held roughly half of global browser market share when exploited in 2014) |
Full article97 words · extracted from blog.talosintelligence.com · click to collapse
Tuesday, April 29, 2014 12:23
Recently several "0day" releases have come out in the security world, and the VRT has released coverage for two critical vulnerabilities, so we wanted to notify you of this coverage so you can use the SIDs to protect your environment.
Microsoft Internet Explorer 0day CVE-2014-1776.
SIDs 30794 & 30803
https://technet.microsoft.com/en-US/library/security/2963983
Adobe Flash 0day CVE-2014-0515
SIDs 30876 & 30877
http://helpx.adobe.com/security/products/flash-player/apsb14-13.html
Coverage for both of these vulnerabilities were released yesterday, April 28, 2014. The latest rule pack will provide the updates for both of these vulnerabilities.
http://blog.snort.org/2014/04/sourcefire-vrt-certified-snort-rules_7339.html
http://blog.snort.org/2014/04/sourcefire-vrt-certified-snort-rules_28.html
Share this post
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/internet-explorer-adobe-flash-0-day/