CVE-2014-1776Active Exploitation(microsoft / internet_explorer)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft internet_explorer systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014. NOTE: this issue originally emphasized VGX.DLL, but Microsoft clarified that "VGX.DLL does not contain the vulnerable code leveraged in this exploit. Disabling VGX.DLL is an exploit-specific workaround that provides an immediate, effective workaround to help block known attacks."

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-07-28. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • internet_explorer
  • windows_7
  • windows_8
  • windows_8.1

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
internet_explorerwindows_7windows_8windows_8.1windows_rtwindows_rt_8.1windows_server_2003windows_server_2008windows_server_2012windows_vista

8 versions affected across 11 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-30: 1Active Exploitation · 2026-04-30: 1Patch / Workaround · 2026-04-30: 1Technical Details · 2026-04-30: 104-30
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • DFIR Lab@DFIR_Lab
    Active Exploitation

    🚨 CRITICAL: CVE-2014-1776 | CVSS 9.8 Use-after-free in IE 6-11 enables remote code execution. Actively exploited in the wild. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/ugHCjEBmb0

    Post summary

    CVE-2014-1776 is a use‑after‑free vulnerability in Internet Explorer 6‑11 that is actively exploited in the wild and requires immediate patching.

    0000021
    11 followersView on X
CPE platform detail20 entries

20 of 20 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftinternet_explorer10--
Appmicrosoftinternet_explorer11--
Appmicrosoftinternet_explorer6--
Appmicrosoftinternet_explorer7--
Appmicrosoftinternet_explorer8--
Appmicrosoftinternet_explorer9--
OSmicrosoftwindows_7---
OSmicrosoftwindows_8---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2003---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2--
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_vista---
OSmicrosoftwindows_xp---
OSmicrosoftwindows_xp---

Explore more