CVE-2014-4138

Microsoft Internet Explorer 11 - Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-4138. PoCs published by Skylined.

AI-analyzed exploit summary This exploit leverages an out-of-bounds write vulnerability in Microsoft Internet Explorer 11 during the conversion of a BMP image to PNG format. The provided SVG file triggers the vulnerability by programmatically copying and pasting an image, leading to potential arbitrary code execution.

Description

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4130 and CVE-2014-4132.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Skylined · doswindows
https://www.exploit-db.com/exploits/40960

This exploit leverages an out-of-bounds write vulnerability in Microsoft Internet Explorer 11 during the conversion of a BMP image to PNG format. The provided SVG file triggers the vulnerability by programmatically copying and pasting an image, leading to potential arbitrary code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Internet Explorer 11.0.9600.16521
No auth needed
Prerequisites: User interaction to open the crafted SVG file · Clipboard access permissions
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70340
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60968
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/40960/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031018
Various Sources x_refsource_misc
http://blog.skylined.nl/20161221001.html

Scores

EPSS 0.3224
EPSS Percentile 98.1%

Details

CWE
CWE-20
Status published
Products (1)
microsoft/internet_explorer 11
Published Oct 15, 2014
Tracked Since Feb 18, 2026