CVE-2014-4123
Microsoft Internet Explorer 10 … 9
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HSummary
CVE-2014-4123 is a high-severity an unspecified weakness vulnerability in Microsoft Windows Server 2008. Its CVSS base score is 8.8 (High).
Operationally, ranked in the top 1% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
Microsoft Internet Explorer versions 7 through 11 contain an elevation of privilege vulnerability, tracked as CVE-2014-4123, that is distinct from the related issue CVE-2014-4124. The flaw permits remote attackers to obtain higher privileges when a user visits a specially crafted web site, carrying a CVSS 3.1 base score of 8.8 reflecting network attack vector, low complexity, and high impact on confidentiality, integrity, and availability.
An attacker can exploit the vulnerability by hosting or compromising a malicious web site and luring a victim to visit it; successful exploitation grants the attacker the ability to run arbitrary code with the privileges of the current user. The issue was observed being exploited in the wild during October 2014.
Microsoft addressed the vulnerability in security bulletin MS14-056, with additional details provided in the October 2014 Security Update blog post and vendor advisories such as Secunia 60968.
The vulnerability saw active exploitation shortly after disclosure, underscoring the need for prompt application of the available patches across supported Internet Explorer installations.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2014-4054
Vulnerability Data
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124.
- CWE(s)
- KEV Date Added
- 25 May 2022
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.