SecPod

Learn Search

Search across all Learn content

← Back to Security Research
CVE-2014-0322: Microsoft Internet Explorer 0-day Vulnerability.

CVE-2014-0322: Microsoft Internet Explorer 0-day Vulnerability.

A use-after-free vulnerability is present in Microsoft Internet Explorer 10 ( CVE-2014-0322 ), which allows remote attackers to execute arbitrary code.

Feb 26, 2014By Thanga Prakash2 min read

A use-after-free vulnerability is present in Microsoft Internet Explorer 10 ( CVE-2014-0322 ), which allows remote attackers to execute arbitrary code.

This vulnerability exploited in the wild as a Watering hole attack, in which the attacker injects a javascript or hidden iframe into a website, which will redirect to a malicious page. Therefore, a good vulnerability management tool can resolve these issues.

In this attack, users who visited the compromised site will encounter an iframe that redirects to the malicious page in the background. However, the below image shows the Wireshark captured traffic of the redirected URL. Vulnerability Management System can prevent these attacks.

Wireshark:

The Redirected page embeds a Flash file, which in turn executes the malicious code.

The loaded Tope.swf file will cause heap sprays with the below data repeatedly.

The below image shows the heap before and after the Heap spray.

The control then is transferred to the javascript from flash file, defined in the tope.as3(Action Script of the Flash file)

Then the javascript will check for EMET.DLL (The Enhanced Mitigation Experience Toolkit) and Internet Explorer 10 from user agent. It will exit the process if the file is present or if it’s not Internet Explorer 10.

Then the control is transferred back to the swf, which will download the payload as tope.jpg and extract two files to the temporary folder.

  • sqlrenew.txt
  • stream.exe (md5: c869c75ed1998294af3c676bdbd56851)

Tope.swf will load the contents of the sqlrenew.txt into memory and this helps in the execution of stream.exe

That stream.exe is creating three more files,

  • stream.exe
    • MediaCenter.exe
      • regsvr32.exe
    • cmd.exe
stream.exe
stream.exe

Next, MediaCenter.exe and cmd.exe processes are getting created, as shown in the below picture.

And MediaCenter.exe looks like a legitimate file and is also digital sign and verified as MICRO DIGITAL INC.

This will finally contact a remote server, oa.ameteksen.com (198.2.209.211), and is in use to send sensitive information.

  • Thanga Prakash

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026