漏洞描述
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014. NOTE: this issue originally emphasized VGX.DLL, but Microsoft clarified that "VGX.DLL does not contain the vulnerable code leveraged in this exploit. Disabling VGX.DLL is an exploit-specific workaround that provides an immediate, effective workaround to help block known attacks."
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.securityfocus.comhttp://www.securityfocus.com/bid/67075↗docs.microsoft.comhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-021↗www.osvdb.orghttp://www.osvdb.org/106311↗securitytracker.comhttp://securitytracker.com/id?1030154↗www.vicarius.iohttps://www.vicarius.io/vsociety/posts/cve-2014-1776-use-after-free-vulnerability-in-microsoft-internet-explorer-detection-script↗blogs.technet.comhttp://blogs.technet.com/b/srd/archive/2014/04/30/protection-strategies-for-the-security-advisory-2963983-ie-0day.aspx↗www.vicarius.iohttps://www.vicarius.io/vsociety/posts/cve-2014-1776-use-after-free-vulnerability-in-microsoft-internet-explorer-mitigation-scripts↗technet.microsoft.comhttps://technet.microsoft.com/library/security/2963983↗www.signalsec.comhttp://www.signalsec.com/cve-2014-1776-ie-0day-analysis/↗secunia.comhttp://secunia.com/advisories/57908↗www.kb.cert.orghttp://www.kb.cert.org/vuls/id/222929↗