CVE-2014-1770

Microsoft Internet Explorer <11 - RCE

Title source: llm

Description

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript code that interacts improperly with a CollectGarbage function call on a CMarkup object allocated by the CMarkup::CreateInitialMarkup function.

Exploits (1)

exploitdb WORKING POC
htmldoswindows_x86
https://www.exploit-db.com/exploits/34010

Scores

EPSS 0.4374
EPSS Percentile 97.5%

Classification

CWE
CWE-399
Status draft

Affected Products (6)

microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer

Timeline

Published May 22, 2014
Tracked Since Feb 18, 2026