Microsoft released MS14-080, a cumulative security update for Internet Explorer that addressed 14 privately reported vulnerabilities across IE 6 through IE 11. The most severe flaws could allow remote code execution if a user visited a specially crafted webpage, with client systems generally rated Critical and affected Windows Server configurations rated Moderate. The bulletin said the update corrected multiple memory corruption issues, two XSS filter bypass flaws, an ASLR bypass, and the VBScript memory corruption bug tracked as CVE-2014-6363.
Microsoft also published MS14-084, another Critical security bulletin, alongside later revisions to the Internet Explorer advisory that required additional updates in some environments, including 3029449 for IE10 on Windows 8, Windows Server 2012, and Windows RT, and 3038314 for IE11 on Windows 7 and Windows Server 2008 R2. The combined advisories highlighted urgent patching needs for Microsoft platforms because successful exploitation could let attackers run arbitrary code through user interaction with malicious content.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On April 14, 2015, Microsoft updated the bulletin to version 3.0 and advised that customers running Internet Explorer 11 on Windows 7 or Windows Server 2008 R2 should also install security update 3038314. This revision added additional remediation guidance for affected systems.
On January 13, 2015, Microsoft re-released MS14-080 to comprehensively address issues related to CVE-2014-6363. Customers running Internet Explorer 10 on Windows 8, Windows Server 2012, or Windows RT were instructed to install both updates 3008923 and 3029449.
On December 9, 2014, Microsoft published cumulative security update 3008923 as MS14-080 to fix fourteen privately reported vulnerabilities in Internet Explorer 6 through 11, including remote code execution, XSS filter bypass, ASLR bypass, and VBScript memory corruption issues. Microsoft said none of the vulnerabilities were publicly disclosed or under active exploitation at the time of release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.