Field Assessment
AI analysis pending.
Exhibit — Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Cross-Reference — CISA KEV
Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.
Ransomware use: Unknown
Added to KEV: 2022-01-28
Required action: Apply updates per vendor instructions.
Original Filing — NVD Description
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014. NOTE: this issue originally emphasized VGX.DLL, but Microsoft clarified that "VGX.DLL does not contain the vulnerable code leveraged in this exploit. Disabling VGX.DLL is an exploit-specific workaround that provides an immediate, effective workaround to help block known attacks."