CVE-2014-1764
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism by leveraging "object confusion" in a broker process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.
- Affected products
- Internet Explorer
- Microsoft Internet Explorer
- = 7, 8, 9, 10, 11
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 37.4% (98th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2014-04-27
CVE-2014-1764 at NVD
1 known exploit for CVE-2014-1764
Proof-of-concept code and exploit modules indexed by Sploitus