CVE detail
CVE-2014-1776
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014. NOTE: this issue originally emphasized VGX.DLL, but Microsoft clarified that "VGX.DLL does not contain the vulnerable code leveraged in this exploit. Disabling VGX.DLL is an exploit-specific workaround that provides an immediate, effective workaround to help block known attacks."
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
22 source links · newest first
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) this week announced the addition of eight more vulnerabilities to the list of security flaws known to be exploited in malicious attacks.
newswww.securityweek.comFeb 1, 2022, 11:12 AMThe US CISA added eight more flaws to its Known Exploited Vulnerabilities Catalog that are known to be used in attacks in the wild. The US Cybersecurity & Infrastructure Security Agency (CISA) has added eight more flaws to the Known Exploited Vulnerabilities Catalog. The ‘Known Exploited Vulnerabilities Catalog‘ is a list of known vulnerabilities that […]
newssecurityaffairs.comJan 31, 2022, 9:05 PM- The evolutions of APT28 attacksSecurity Affairs
Analyzing how tactics, techniques and procedures of the Russia-linked APT28 cyberespionage group evolve over the time. APT28 is a well known Russian cyber espionage group attributed, with a medium level of confidence, to Russian military intelligence agency GRU (by CrowdStrike). It is also known as Sofacy Group (by Kaspersky) or STRONTIUM (by Microsoft) and it’s used to target Aereospace, Defence, Governmente Agencies, International […]
newssecurityaffairs.comDec 5, 2019, 6:41 AM A June 23 FireEye blog post titled “Operation Clandestine Wolf” discussed a cyber espionage group, known as APT3, that had been exploiting a zero-day vulnerability in Adobe Flash. Unit 42 also tracks the APT3 group using the name UPS, which is an intrusion set with Chinese origins that is known for having early access to
vendorunit42.paloaltonetworks.comJul 27, 2015, 10:50 AM- Elusive HanJuan EK Drops New Tinba Version (updated)Malwarebytes Labs
Update 07/03/15: AdFly contacted us and we are publishing their statement below: We are sorry for the inconvenience but this is…
newswww.malwarebytes.comJun 23, 2015, 5:00 PM Continuing a recent trend in which Internet Explorer vulnerabilities are exploited using Flash, samples of an SWF purportedly used in conjunction with CVE-2014-6332 have appeared in several places. The most famous examples of this trend are the exploits for CVE-2014-0322 and CVE-2014-1776. We have yet to encounter the SWF sample with its original exploit attached,
vendorunit42.paloaltonetworks.comNov 26, 2014, 10:00 PM- Exposing the Flash ‘EITest’ malware campaignMalwarebytes Labs
Security incidents seldom are unrelated. Connecting those dots can help us better understand the underlying architecture and groups involved in cyber-crime.Since early July,…
newswww.malwarebytes.comOct 28, 2014, 5:00 PM After analyzing public vulnerabilities and exploit trends in the first half of 2014, Bromium Labs concluded that Internet Explorer is the “sweet spot for attackers.” “Internet Explorer was the most patched and also one of the most exploited products,” the report (pdf) states. Microsoft’s browser “set a record high for reported vulnerabilities in the first […]
newswww.csoonline.comJul 23, 2014, 3:23 PMUse-after-free bugs have affected Internet Explorer for years. In the past year alone, Microsoft patched 122 IE vulnerabilities, the majority of which were use-after-free bugs. This year Microsoft has already patched 126 IE vulnerabilities to date. Of those vulnerabilities, 4 were actively being exploited in the wild. These 4 exploits (CVE-2014-1815, CVE-2014-1776, CVE-2014-0322, CVE-2014-0324) were
vendorunit42.paloaltonetworks.comJul 17, 2014, 2:45 AMToday, Microsoft patched 59 Internet Explorer vulnerabilities, 21 of them discovered by Palo Alto Networks researchers. Palo Alto Networks is committed not only to detecting attacks, but preventing them as well. Our internal research team discovered each of these 21 vulnerabilities and reported them to Microsoft so they could begin building and testing patches. Microsoft
vendorunit42.paloaltonetworks.comJun 10, 2014, 6:15 PMIn February, Microsoft awarded $100,000 to Yu Yang (@Tombkeeper) for reporting a new mitigation bypass technique as part of Microsoft’s Bounty Program. Yu later demonstrated his research at CanSecWest in March. In his slides, he mentioned that a "god mode" of Internet Explorer could be turned on by a one byte overwrite. However, he had
vendorunit42.paloaltonetworks.comJun 6, 2014, 2:10 PMMicrosoft and Adobe Systems released security updates today to fix a number of critical vulnerabilities.
newswww.securityweek.comMay 13, 2014, 7:14 PM- Microsoft to release eight bulletins on TuesdayHelp Net Security
Tuesday, May 13 marks the next Microsoft security patch release. This release will contain eight bulletins, which is the most in a single release so far this year. The good news is that each of these bulletins only address a few CVEs at most. This release will address vulnerabilities in SharePoint, Internet Explorer, Microsoft Office and Microsoft Windows. Only the bulletins for SharePoint and Internet Explorer are rated “Critical”; the rest of the bulletins are … More →
newswww.helpnetsecurity.comMay 9, 2014, 5:22 AM Summary The exploit code used in the recent CVE-2014-1776 attacks shares many similar characteristics with code that exploited CVE-2014-0322 and CVE-2013-3163. The shared techniques, variable names and code structure suggest these exploits share a common author or template. Palo Alto Networks customers are protected by from exploitation of CVE-2014-1776 with content release 433-2194. Late last
vendorunit42.paloaltonetworks.comMay 2, 2014, 10:31 PMAttackers are exploiting a recently disclosed zero-day vulnerability in Internet Explorer in campaigns targeting Windows XP users, FireEye researchers have found.
newswww.securityweek.comMay 1, 2014, 11:53 PMSummary Critical vulnerability (CVE-2014-1776) identified in Internet Explorer, with active attacks observed in the wild IE vulnerability could be used to exploit multiple versions of Internet Explorer, including those on Windows-XP based systems, which no longer receive security updates from Microsoft Palo Alto Networks Threat Prevention customers are protected from exploitation of the vulnerability Cyvera endpoint
vendorunit42.paloaltonetworks.comApr 29, 2014, 3:32 PMCompanies have several options for defending against a recently discovered zero-day vulnerability in Internet Explorer and experts say businesses should get started immediately. Over the weekend, security vendor FireEye found an exploit aimed at defense and financial services companies using IE9 through IE11. The exploit was found in a “very popular U.S. website,” which has […]
newswww.csoonline.comApr 28, 2014, 11:29 PM- IE 0-day exploit actively used in attacks against US-based firmsHelp Net Security
Late on Saturday, Microsoft has published a security advisory warning about “limited, targeted attacks” exploiting a newly discovered zero day vulnerability that affects all supported versions of Internet Explorer (6 to 11). “This issue allows remote code execution if users visit a malicious website with an affected browser. This would typically occur by an attacker convincing someone to click a link in an email or instant message,” shared in a blog post Dustin Childs, Group … More →
newswww.helpnetsecurity.comApr 28, 2014, 7:46 AM “Microsoft is aware of limited, targeted attacks that attempt to exploit a vulnerability in Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet Explorer 11,” states a security advisory for CVE-2014-1776 that Microsoft released late on Saturday. FireEye Research Labs identified this new zero-day that is actively […]
newswww.csoonline.comApr 27, 2014, 6:53 PMResearchers from FireEye have discovered a nasty zero-day exploit that bypasses the ASLR and DEP protections in Microsoft Windows and is being used in targeted attacks.
newswww.securityweek.comApr 27, 2014, 6:06 PM- Microsoft warns against new Internet Explorer Zero-Day UPDATEDMalwarebytes Labs
Update (May 1, 2014): Microsoft has decided to release an out-of-band security update for CVE-2014-1776 and, in a surprising move, is also…
newswww.malwarebytes.comApr 27, 2014, 5:00 PM - FireEye discovered a new zero-day exploit for IE in the wild – Operation Clandestine FoxSecurity Affairs
FireEye Research Labs has identified a new IE zero-day vulnerability exploited in a series of targeted attacks part of the Operation Clandestine Fox. FireEye Research Labs has identified a new Internet Explorer (IE) zero-day vulnerability exploited in a series of targeted attacks. The zero-day flaw affects a wide range of versions of the popular browser, […]
newssecurityaffairs.comApr 27, 2014, 10:59 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2013-5056CVSS 9.3 · Critical
Use-after-free vulnerability in the Scripting Runtime Object Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R…
- CVE-2013-3897CVSS 8.8 · High
Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a de…
- CVE-2015-2360CVSS 8.8 · High
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1…
- CVE-2015-1726CVSS 7.2 · High
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wind…
- CVE-2015-1724CVSS 7.2 · High
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wind…
- CVE-2015-1723CVSS 7.2 · High
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wind…