Vulnerability record · CVE-2014-0282 · published 11 June 2014
CVE-2014-0282: Internet Explorer memory corruption allows remote code execution
Microsoft · Internet Explorer
CVE-2014-0282 is a memory corruption flaw in Microsoft Internet Explorer 6 through 11 that can be triggered when a user views a crafted web page. Successful exploitation allows arbitrary code execution in the context of the browser, or a denial of service. It is one of several similar IE memory corruption issues patched in mid-2014.
Description
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1775, CVE-2014-1779, CVE-2014-1799, CVE-2014-1803, and CVE-2014-2757.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with a high EPSS score and public exploit code, though the affected product is legacy and no KEV listing is present.
What it is
CVE-2014-0282 is a memory corruption flaw in Microsoft Internet Explorer 6 through 11 that can be triggered when a user views a crafted web page. Successful exploitation allows arbitrary code execution in the context of the browser, or a denial of service. It is one of several similar IE memory corruption issues patched in mid-2014.
Impact
An attacker can execute arbitrary code with the privileges of the logged-on user, or crash the browser. Because IE often runs with user-level rights, the practical impact depends on the victim's privileges and any additional mitigations.
Attack surface
Reached over the network via a crafted website that the victim must visit; no authentication is required, but user interaction (browsing to the page) is needed. The CVSS vector AV:N/AC:M/Au:N indicates remote, medium complexity, unauthenticated access.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.50948, 98.9th percentile), and an Exploit-DB entry exists, indicating public exploit code is available.
What to do
- Apply Microsoft security update MS14-035 (or later cumulative IE updates) to all affected Internet Explorer versions.
- Upgrade or migrate off Internet Explorer 6 through 11, which are no longer supported on current Windows platforms.
- Enforce EMET or Windows Defender Exploit Guard mitigations such as DEP, ASLR and Control Flow Guard for legacy IE where it must remain.
- Restrict browsing to trusted sites and block known malicious or untrusted content via web filtering and proxy controls.
- Disable or remove unnecessary IE components and ActiveX controls to reduce the attack surface.
Detection
- Monitor for IE crashes (Event ID 1000/1001) and unexpected process terminations on endpoints still running IE.
- Hunt for suspicious child processes spawned by iexplore.exe, such as cmd.exe, powershell.exe or script hosts.
- Review proxy and DNS logs for access to known exploit-hosting domains or pages matching public PoC patterns.
- Use EDR to alert on memory corruption indicators, ROP-like behavior or shellcode execution within IE processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-0282 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-0282), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.