Cyber Resilience

CVE-2014-4123

Microsoft Internet Explorer 10 … 9

CISA KEVActive ExploitationEUVD Exploited
Published
15 October 2014
Modified
21 April 2026
KEV Added
25 May 2022
Patch / advisory
CVSS Score v3.1 8.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.47 99th percentile
Risk Priority 90 floored blend · peak EPSS

Summary

CVE-2014-4123 is a high-severity an unspecified weakness vulnerability in Microsoft Windows Server 2008. Its CVSS base score is 8.8 (High).

Operationally, ranked in the top 1% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

Microsoft Internet Explorer versions 7 through 11 contain an elevation of privilege vulnerability, tracked as CVE-2014-4123, that is distinct from the related issue CVE-2014-4124. The flaw permits remote attackers to obtain higher privileges when a user visits a specially crafted web site, carrying a CVSS 3.1 base score of 8.8 reflecting network attack vector, low complexity, and high impact on confidentiality, integrity, and availability.

An attacker can exploit the vulnerability by hosting or compromising a malicious web site and luring a victim to visit it; successful exploitation grants the attacker the ability to run arbitrary code with the privileges of the current user. The issue was observed being exploited in the wild during October 2014.

Microsoft addressed the vulnerability in security bulletin MS14-056, with additional details provided in the October 2014 Security Update blog post and vendor advisories such as Secunia 60968.

The vulnerability saw active exploitation shortly after disclosure, underscoring the need for prompt application of the available patches across supported Internet Explorer installations.

EU & UK References

Vulnerability Data

Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124.

CWE(s)
KEV Date Added
25 May 2022

Related Threats

CVEs Like This One

CVE-2013-7331Same product: Microsoft Internet Explorerboth on KEV
CVE-2014-2817Same product: Microsoft Internet Explorerboth on KEV
CVE-2014-1776Same product: Microsoft Internet Explorerboth on KEV
CVE-2014-4148Same product: Microsoft Windows 7both on KEV
CVE-2015-2360Same product: Microsoft Windows 7both on KEV
CVE-2014-6332Same product: Microsoft Windows 7both on KEV
CVE-2015-0071Same product: Microsoft Internet Explorerboth on KEV
CVE-2014-4113Same product: Microsoft Windows 7both on KEV
CVE-2015-2387Same product: Microsoft Windows 7both on KEV
CVE-2013-3918Same product: Microsoft Windows 7both on KEV

Affected Assets

microsoft
internet explorer
10, 11, 7, 8, 9

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References