RULE(RULE ID:306506)

Rule General Information
Release Date: 2018-08-14
Rule Name: Microsoft Internet Explorer TextRange Use After Free Vulnerability (CVE-2014-0307)
Severity:
CVE ID:
Rule Protection Details
Description: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a certain sequence of manipulations of a TextRange element, aka "Internet Explorer Memory Corruption Vulnerability."
Impact: A use-after-free vulnerability can be exploited by an attacker in the vulnerable product. Successful exploit may cause some adverse consequences, such as crash of the product, execution of arbitrary code.
Affected OS: Network Device, Solaris, FreeBSD, Windows, Mac OS, iOS, Other Unix, Linux, Others, Android
Reference: MicrosoftSecurityBulletin:MS14-012
ExploitDB:32438
Solutions
Microsoft has released a patch MS14-012 to eliminate the vulnerability. The patch can be downloaded at:
http://technet.microsoft.com/security/bulletin/MS14-012