Vulnerability record · CVE-2014-1776 · published 27 April 2014
CVE-2014-1776: Internet Explorer use-after-free in CMarkup::IsConnectedToPrimaryMarkup
Microsoft · Internet Explorer
Microsoft Internet Explorer 6 through 11 contains a use-after-free in the CMarkup::IsConnectedToPrimaryMarkup function that allows remote code execution or memory corruption denial of service. It was exploited in the wild in April 2014, and Microsoft clarified that VGX.DLL does not hold the vulnerable code, though disabling it was an effective exploit-specific workaround. The flaw matters because it is remotely reachable, unauthenticated, and gives full code execution on affected browsers.
Description
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014. NOTE: this issue originally emphasized VGX.DLL, but Microsoft clarified that "VGX.DLL does not contain the vulnerable code leveraged in this exploit. Disabling VGX.DLL is an exploit-specific workaround that provides an immediate, effective workaround to help block known attacks."
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityRemote unauthenticated code execution in a widely deployed browser, confirmed exploited in the wild and listed in CISA KEV with a very high EPSS score.
What it is
Microsoft Internet Explorer 6 through 11 contains a use-after-free in the CMarkup::IsConnectedToPrimaryMarkup function that allows remote code execution or memory corruption denial of service. It was exploited in the wild in April 2014, and Microsoft clarified that VGX.DLL does not hold the vulnerable code, though disabling it was an effective exploit-specific workaround. The flaw matters because it is remotely reachable, unauthenticated, and gives full code execution on affected browsers.
Impact
An attacker can execute arbitrary code in the context of the IE process or crash it, yielding full control of confidentiality, integrity and availability on the victim host.
Attack surface
Reached over the network via a crafted web page or content rendered by Internet Explorer; the CVSS vector shows no privileges required and no user interaction, though in practice a victim must load attacker-controlled content in IE.
Exploitation
Listed in CISA KEV since 2022-01-28 with a required action to apply vendor updates, and EPSS 30-day probability is 0.88013 (99.757th percentile); references include an exploit analysis and a zero-day report, confirming active exploitation.
What to do
- Apply Microsoft security update MS14-021 (KB2964358) to all affected IE versions immediately.
- If patching cannot be completed, apply the Microsoft workaround of disabling the VGX.DLL module, which blocks known attacks.
- Retire or restrict Internet Explorer usage; migrate users to a supported browser.
- Enforce EMET or equivalent exploit mitigations on systems that must still run IE.
- Block or inspect network traffic delivering exploit content to IE clients.
Detection
- Monitor for IE process crashes and memory corruption events consistent with use-after-free exploitation.
- Hunt for suspicious child processes spawned by iexplore.exe, especially script interpreters or command shells.
- Review proxy and IDS logs for known exploit delivery patterns and malicious pages targeting IE.
- Audit endpoints for unpatched IE versions and for VGX.DLL being enabled where the workaround is required.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2014-1776 to the Known Exploited Vulnerabilities catalog on 28 January 2022 as "Microsoft Internet Explorer Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 28 July 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-1776 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-1776), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.