CVE-2014-0322: Microsoft Internet Explorer Use-After-Free Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-05-04. EPSS: 85.1% chance of exploitation in the next 30 days.

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014.

Affected products

  • Microsoft Internet Explorer: version 9 only; version 10 only

Published 2014-02-14. Last modified 2026-06-17.