Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-1762.
AI-analyzed exploit summary This is a functional proof-of-concept exploit for a use-after-free vulnerability in Internet Explorer 9 and 10. The exploit triggers a memory corruption by manipulating the CFormElement object through JavaScript, leading to potential arbitrary code execution.
Description
Unspecified vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code with medium-integrity privileges and bypass a sandbox protection mechanism via unknown vectors, as demonstrated by ZDI during a Pwn4Fun competition at CanSecWest 2014.
Exploits (1)
This is a functional proof-of-concept exploit for a use-after-free vulnerability in Internet Explorer 9 and 10. The exploit triggers a memory corruption by manipulating the CFormElement object through JavaScript, leading to potential arbitrary code execution.