Vulnerability record · CVE-2014-0307 · published 12 March 2014
CVE-2014-0307: Internet Explorer 9 TextRange use-after-free memory corruption
Microsoft · Internet Explorer
CVE-2014-0307 is a use-after-free vulnerability in Microsoft Internet Explorer 9 triggered by a specific sequence of manipulations of a TextRange element. Successful exploitation causes memory corruption that can lead to arbitrary code execution or a denial of service. It matters because IE 9 was widely deployed at the time and the flaw is remotely reachable with no authentication.
Description
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a certain sequence of manipulations of a TextRange element, aka "Internet Explorer Memory Corruption Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with a public exploit and very high EPSS, but limited to the legacy IE 9 browser and not confirmed in KEV.
What it is
CVE-2014-0307 is a use-after-free vulnerability in Microsoft Internet Explorer 9 triggered by a specific sequence of manipulations of a TextRange element. Successful exploitation causes memory corruption that can lead to arbitrary code execution or a denial of service. It matters because IE 9 was widely deployed at the time and the flaw is remotely reachable with no authentication.
Impact
An attacker can execute arbitrary code in the context of the affected browser process, or crash it to cause a denial of service. Code execution would give the attacker the privileges of the logged-on user.
Attack surface
Reached over the network via a crafted web page or content that manipulates a TextRange element; the CVSS vector AV:N/AC:M/Au:N indicates no authentication is required, though some user interaction (typically visiting the page) is implied by the medium access complexity.
Exploitation
A public exploit exists per the Exploit-DB reference, and EPSS is 0.72239 (99.4th percentile), indicating high predicted exploitation activity. The vulnerability is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded in that catalog.
What to do
- Apply Microsoft security bulletin MS14-012, which addresses this vulnerability.
- Upgrade from Internet Explorer 9 to a supported, patched browser version.
- Enforce EMET or equivalent exploit mitigations on legacy IE deployments where upgrade is not immediately possible.
- Restrict or block browsing to untrusted sites from systems still running IE 9.
Detection
- Monitor for IE 9 process crashes (iexplore.exe) with memory corruption signatures consistent with use-after-free.
- Hunt for exploit-db 32438 payload patterns or known shellcode indicators in network or endpoint telemetry.
- Review proxy and DNS logs for users on IE 9 accessing newly registered or low-reputation domains.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-0307 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-0307), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.