Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft Internet Explorer 9 및 10의 해제 후 사용 취약점으로 인해 원격 공격자가 조작된 JavaScript 코드, CMarkup 및 script 요소의 onpropertychange 속성과 관련된 벡터를 통해 임의 코드를 실행할 수 있으며, 이는 2014년 1월과 2월 실제로 악용되었다.
Microsoft Internet Explorer 9 및 10의 해제 후 사용 취약점으로 인해 원격 공격자가 조작된 JavaScript 코드, CMarkup 및 script 요소의 onpropertychange 속성과 관련된 벡터를 통해 임의 코드를 실행할 수 있으며, 이는 2014년 1월과 2월 실제로 악용되었다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014.