CVE-2014-0322 is a critical use-after-free vulnerability in Microsoft Internet Explorer versions 9 and 10, impacting various Windows operating systems. This flaw allows remote attackers to execute arbitrary code by tricking users into visiting a malicious website containing crafted JavaScript and CMarkup. With a CVSS score of 8.8 (High) and an EPSS score indicating high exploitability, successful exploitation grants attackers full control over the affected system. The vulnerability was actively exploited in the wild in early 2014, with publicly available Metasploit modules and significant community discussion and media coverage confirming its widespread impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.