Unrated severityNVD Advisory· Published Apr 27, 2014· Updated May 6, 2026
CVE-2014-1766
CVE-2014-1766
Description
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at CanSecWest 2014. NOTE: the original disclosure referred to triggering a kernel bug with the Internet Explorer exploit payload, but this ID is not for a kernel vulnerability.
Affected products
3cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-035nvdPatchVendor Advisory
- twitter.com/thezdi/statuses/444216845734666240nvdThird Party Advisory
- www.pwn2own.com/2014/03/pwn2own-results-thursday-day-two/nvdBroken LinkThird Party Advisory
- www.securityfocus.com/bid/67518nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1030370nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.