Microsoft IE Behavior:URL Use-after-free Vulnerability

Strike ID:
E14-8h801
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
3456
Year:
2014

Description

This strike exploits a use-after-free vulnerability in Microsoft Internet Explorer (IE). The vulnerability is triggered when an attempt is made to access a previously deleted object while processing behavior behavior properties within an html body element. By enticing a user to view a malicious web page, an attacker can remotely execute arbitrary code.

CVE

Bid