Vulnerability record · CVE-2014-0322 · published 14 February 2014
CVE-2014-0322: Microsoft Internet Explorer use-after-free allows remote code execution
Microsoft · Internet Explorer
Internet Explorer 9 and 10 contain a use-after-free (CWE-416) flaw reachable through crafted JavaScript involving CMarkup and the onpropertychange attribute of a script element. Successful exploitation lets a remote attacker run arbitrary code in the context of the browsing user, and the flaw was exploited in the wild in January and February 2014.
Description
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is listed in CISA KEV as exploited in the wild, has a very high EPSS score, and public exploit code exists, so unpatched IE 9/10 systems face immediate compromise risk.
What it is
Internet Explorer 9 and 10 contain a use-after-free (CWE-416) flaw reachable through crafted JavaScript involving CMarkup and the onpropertychange attribute of a script element. Successful exploitation lets a remote attacker run arbitrary code in the context of the browsing user, and the flaw was exploited in the wild in January and February 2014.
Impact
An attacker gains arbitrary code execution with the privileges of the logged-on user, which can lead to full system compromise depending on that user's rights. The record does not state any additional impact beyond code execution.
Attack surface
Reached over the network via a crafted web page or script; the CVSS vector shows no privileges required but user interaction required, so a victim must browse to or be lured to attacker-controlled content. No authentication is needed by the attacker.
Exploitation
CISA KEV lists it as exploited in the wild (added 2022-05-04), EPSS 30-day probability is 0.85175 (99.7th percentile), and references include Exploit-DB entries and a public exploit archive, indicating mature public exploitation. KEV notes no known ransomware campaign use.
What to do
- Apply the Microsoft fix in MS14-012 (security advisory 2934088) or later cumulative updates for affected IE versions.
- Retire or upgrade Internet Explorer 9 and 10; migrate users to a supported browser.
- Enforce EMET or equivalent exploit mitigations on systems that must still run affected IE versions.
- Restrict or block outbound browsing to untrusted sites and filter malicious script content at the network edge.
- Disable or restrict ActiveX and script execution where business needs allow.
Detection
- Hunt for IE 9/10 processes spawning child processes or making unexpected network connections, which can indicate post-exploitation activity.
- Monitor for crashes in mshtml.dll or IE rendering components consistent with use-after-free exploitation.
- Review proxy and DNS logs for watering-hole or exploit-delivery domains tied to known campaigns against this CVE.
- Alert on known public exploit signatures for CVE-2014-0322 in IDS/IPS and endpoint telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2014-0322 to the Known Exploited Vulnerabilities catalog on 4 May 2022 as "Microsoft Internet Explorer Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 25 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-0322 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-0322), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.