HIGH KEV
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124
Published Oct 15, 2014 ·Due Jun 15, 2022
8.8
HIGHCVSS 3.1
EPSS 47.13%
Description
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124.
Affected products
No data.
Configuration 1
AND
- 7
Running on/with
OR
- n/a
- n/a
- n/a
Configuration 2
AND
- 8
Running on/with
OR
- n/a
- n/a
- n/a
- r2
- r2
- n/a
Configuration 3
AND
- 9
Running on/with
OR
- n/a
- n/a
- r2
- n/a
Configuration 4
AND
- 10
Running on/with
OR
- n/a
- n/a
- n/a
- r2
- n/a
Configuration 5
AND
- 11
Running on/with
OR
- n/a
- n/a
- n/a
- r2
- r2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (6)
- http://blogs.technet.com/b/srd/archive/2014/10/14/accessing-risk-for-the-october-2014-security-updates.aspx x_refsource_CONFIRMNot ApplicableVendor Advisory
- http://secunia.com/advisories/60968 third-party-advisoryx_refsource_SECUNIABroken Link
- http://www.securityfocus.com/bid/70326 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1031018 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-056 vendor-advisoryx_refsource_MSPatchVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-4123 government-resourceUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| http://blogs.technet.com/b/srd/archive/2014/10/14/accessing-risk-for-the-october-2014-security-updates.aspx | x_refsource_CONFIRMNot ApplicableVendor Advisory | |
| http://secunia.com/advisories/60968 | third-party-advisoryx_refsource_SECUNIABroken Link | |
| http://www.securityfocus.com/bid/70326 | vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1031018 | vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry | |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-056 | vendor-advisoryx_refsource_MSPatchVendor Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-4123 | government-resourceUS Government Resource |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published Oct 15, 2014
Updated Oct 22, 2025
Reserved Jun 12, 2014
Link CVE-2014-4123
CISA Vulnrichment
Updated Feb 10, 2025