HTTP: Microsoft Internet Explorer Letter Style UAF (CVE-2014-4050)

This signature detects an attempt to exploit a known vulnerability against Microsoft Internet Explorer. Successful exploitation could allow an attacker to execute arbitrary codes into the context of the running application.

Extended Description

Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2796, CVE-2014-2808, CVE-2014-2825, CVE-2014-4055, and CVE-2014-4067.

Affected Products

Microsoft internet_explorer

References

BugTraq: 69125

CVE: CVE-2014-4050

Short Name
HTTP:STC:IE:LETTER-STYLE-UAF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
(CVE-2014-4050) CVE-2014-4050 Explorer Internet Letter Microsoft Style UAF bid:69125
Release Date
10/06/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Microsoft

CVSS Score

9.3

Found a potential security threat?