Skip to main content

CVE detail

CVE-2014-1776

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014. NOTE: this issue originally emphasized VGX.DLL, but Microsoft clarified that "VGX.DLL does not contain the vulnerable code leveraged in this exploit. Disabling VGX.DLL is an exploit-specific workaround that provides an immediate, effective workaround to help block known attacks."

CVSS 9.8 · CriticalBuzz score 71.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 71.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
22 evidence mentions in the snapshot
Diversity score
16.0
6 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
22 source links · newest first
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) this week announced the addition of eight more vulnerabilities to the list of security flaws known to be exploited in malicious attacks.

    newswww.securityweek.comFeb 1, 2022, 11:12 AM
  • The US CISA added eight more flaws to its Known Exploited Vulnerabilities Catalog that are known to be used in attacks in the wild. The US Cybersecurity & Infrastructure Security Agency (CISA) has added eight more flaws to the Known Exploited Vulnerabilities Catalog. The ‘Known Exploited Vulnerabilities Catalog‘ is a list of known vulnerabilities that […]

    newssecurityaffairs.comJan 31, 2022, 9:05 PM
  • The evolutions of APT28 attacksSecurity Affairs

    Analyzing how tactics, techniques and procedures of the Russia-linked APT28 cyberespionage group evolve over the time. APT28 is a well known Russian cyber espionage group attributed, with a medium level of confidence, to Russian military intelligence agency GRU (by CrowdStrike). It is also known as Sofacy Group (by Kaspersky) or STRONTIUM (by Microsoft) and it’s used to target Aereospace, Defence, Governmente Agencies, International […]

    newssecurityaffairs.comDec 5, 2019, 6:41 AM
  • A June 23 FireEye blog post titled “Operation Clandestine Wolf” discussed a cyber espionage group, known as APT3, that had been exploiting a zero-day vulnerability in Adobe Flash. Unit 42 also tracks the APT3 group using the name UPS, which is an intrusion set with Chinese origins that is known for having early access to

    vendorunit42.paloaltonetworks.comJul 27, 2015, 10:50 AM
  • Update 07/03/15: AdFly contacted us and we are publishing their statement below: We are sorry for the inconvenience but this is…

    newswww.malwarebytes.comJun 23, 2015, 5:00 PM
  • Continuing a recent trend in which Internet Explorer vulnerabilities are exploited using Flash, samples of an SWF purportedly used in conjunction with CVE-2014-6332 have appeared in several places. The most famous examples of this trend are the exploits for CVE-2014-0322 and CVE-2014-1776. We have yet to encounter the SWF sample with its original exploit attached,

    vendorunit42.paloaltonetworks.comNov 26, 2014, 10:00 PM
  • Exposing the Flash ‘EITest’ malware campaignMalwarebytes Labs

    Security incidents seldom are unrelated. Connecting those dots can help us better understand the underlying architecture and groups involved in cyber-crime.Since early July,…

    newswww.malwarebytes.comOct 28, 2014, 5:00 PM
  • After analyzing public vulnerabilities and exploit trends in the first half of 2014, Bromium Labs concluded that Internet Explorer is the “sweet spot for attackers.” “Internet Explorer was the most patched and also one of the most exploited products,” the report (pdf) states. Microsoft’s browser “set a record high for reported vulnerabilities in the first […]

    newswww.csoonline.comJul 23, 2014, 3:23 PM
  • Use-after-free bugs have affected Internet Explorer for years. In the past year alone, Microsoft patched 122 IE vulnerabilities, the majority of which were use-after-free bugs. This year Microsoft has already patched 126 IE vulnerabilities to date. Of those vulnerabilities, 4 were actively being exploited in the wild. These 4 exploits (CVE-2014-1815, CVE-2014-1776, CVE-2014-0322, CVE-2014-0324) were

    vendorunit42.paloaltonetworks.comJul 17, 2014, 2:45 AM
  • Today, Microsoft patched 59 Internet Explorer vulnerabilities, 21 of them discovered by Palo Alto Networks researchers. Palo Alto Networks is committed not only to detecting attacks, but preventing them as well. Our internal research team discovered each of these 21 vulnerabilities and reported them to Microsoft so they could begin building and testing patches. Microsoft

    vendorunit42.paloaltonetworks.comJun 10, 2014, 6:15 PM
  • In February, Microsoft awarded $100,000 to Yu Yang (@Tombkeeper) for reporting a new mitigation bypass technique as part of Microsoft’s Bounty Program. Yu later demonstrated his research at CanSecWest in March. In his slides, he mentioned that a "god mode" of Internet Explorer could be turned on by a one byte overwrite. However, he had

    vendorunit42.paloaltonetworks.comJun 6, 2014, 2:10 PM
  • Microsoft and Adobe Systems released security updates today to fix a number of critical vulnerabilities.

    newswww.securityweek.comMay 13, 2014, 7:14 PM
  • Microsoft to release eight bulletins on TuesdayHelp Net Security

    Tuesday, May 13 marks the next Microsoft security patch release. This release will contain eight bulletins, which is the most in a single release so far this year. The good news is that each of these bulletins only address a few CVEs at most. This release will address vulnerabilities in SharePoint, Internet Explorer, Microsoft Office and Microsoft Windows. Only the bulletins for SharePoint and Internet Explorer are rated “Critical”; the rest of the bulletins are … More →

    newswww.helpnetsecurity.comMay 9, 2014, 5:22 AM
  • Summary The exploit code used in the recent CVE-2014-1776 attacks shares many similar characteristics with code that exploited CVE-2014-0322 and CVE-2013-3163. The shared techniques, variable names and code structure suggest these exploits share a common author or template. Palo Alto Networks customers are protected by from exploitation of CVE-2014-1776 with content release 433-2194. Late last

    vendorunit42.paloaltonetworks.comMay 2, 2014, 10:31 PM
  • Attackers are exploiting a recently disclosed zero-day vulnerability in Internet Explorer in campaigns targeting Windows XP users, FireEye researchers have found.

    newswww.securityweek.comMay 1, 2014, 11:53 PM
  • Summary Critical vulnerability (CVE-2014-1776) identified in Internet Explorer, with active attacks observed in the wild IE vulnerability could be used to exploit multiple versions of Internet Explorer, including those on Windows-XP based systems, which no longer receive security updates from Microsoft Palo Alto Networks Threat Prevention customers are protected from exploitation of the vulnerability Cyvera endpoint

    vendorunit42.paloaltonetworks.comApr 29, 2014, 3:32 PM
  • Companies have several options for defending against a recently discovered zero-day vulnerability in Internet Explorer and experts say businesses should get started immediately. Over the weekend, security vendor FireEye found an exploit aimed at defense and financial services companies using IE9 through IE11. The exploit was found in a “very popular U.S. website,” which has […]

    newswww.csoonline.comApr 28, 2014, 11:29 PM
  • Late on Saturday, Microsoft has published a security advisory warning about “limited, targeted attacks” exploiting a newly discovered zero day vulnerability that affects all supported versions of Internet Explorer (6 to 11). “This issue allows remote code execution if users visit a malicious website with an affected browser. This would typically occur by an attacker convincing someone to click a link in an email or instant message,” shared in a blog post Dustin Childs, Group … More →

    newswww.helpnetsecurity.comApr 28, 2014, 7:46 AM
  • “Microsoft is aware of limited, targeted attacks that attempt to exploit a vulnerability in Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet Explorer 11,” states a security advisory for CVE-2014-1776 that Microsoft released late on Saturday. FireEye Research Labs identified this new zero-day that is actively […]

    newswww.csoonline.comApr 27, 2014, 6:53 PM
  • Researchers from FireEye have discovered a nasty zero-day exploit that bypasses the ASLR and DEP protections in Microsoft Windows and is being used in targeted attacks.

    newswww.securityweek.comApr 27, 2014, 6:06 PM
  • Update (May 1, 2014): Microsoft has decided to release an out-of-band security update for CVE-2014-1776 and, in a surprising move, is also…

    newswww.malwarebytes.comApr 27, 2014, 5:00 PM
  • FireEye Research Labs has identified a new IE zero-day vulnerability exploited in a series of targeted attacks part of the Operation Clandestine Fox. FireEye Research Labs has identified a new Internet Explorer (IE) zero-day vulnerability exploited in a series of targeted attacks. The zero-day flaw affects a wide range of versions of the popular browser, […]

    newssecurityaffairs.comApr 27, 2014, 10:59 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence