漏洞描述
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
technet.microsoft.comhttp://technet.microsoft.com/security/advisory/2934088↗www.fireeye.comhttp://www.fireeye.com/blog/uncategorized/2014/02/operation-snowman-deputydog-actor-compromises-us-veterans-of-foreign-wars-website.html↗www.dropbox.comhttps://www.dropbox.com/s/pyxjgycmudirbqe/CVE-2014-0322.zip↗docs.microsoft.comhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-012↗www.osvdb.orghttp://www.osvdb.org/103354↗www.kb.cert.orghttp://www.kb.cert.org/vuls/id/732479↗twitter.comhttp://twitter.com/nanoc0re/statuses/434251658344673281↗