Microsoft Internet Explorer CMarkup Object Use-After-Free Exploit (MS14-021) Update 2

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in the wild in April 2014. This update solves an issue with the Internet Explorer version detection the module executes, that may show an error message in the browser and an indication of the browser not being supported in the web server module log, even when the version of the target browser is actually supported.
Exploit type: 
Platform: 
Vulnerabilty ID: 
CVE-2014-1776
Product Version: 
2014_R1
Released Date: 
Wednesday, July 23, 2014 - 00:00