« Back to list

CVE-2014-2783

Status: ModifiedMedium (6.4)—

Microsoft Internet Explorer 7 through 11 does not prevent use of wildcard EV SSL certificates, which might allow remote attackers to spoof a trust level by leveraging improper issuance of a wildcard certificate by a recognized Certification Authority, aka "Extended Validation (EV) Certificate Security Feature Bypass Vulnerability."

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2014-2783",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-07-08T22:55:06.567",
  "references": [
    {
      "url": "http://secunia.com/advisories/59775",
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/68391",
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1030532",
      "source": "secure@microsoft.com"
    },
    {
      "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-037",
      "source": "secure@microsoft.com"
    },
    {
      "url": "http://secunia.com/advisories/59775",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/68391",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1030532",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-037",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Microsoft Internet Explorer 7 through 11 does not prevent use of wildcard EV SSL certificates, which might allow remote attackers to spoof a trust level by leveraging improper issuance of a wildcard certificate by a recognized Certification Authority, aka \"Extended Validation (EV) Certificate Security Feature Bypass Vulnerability.\""
    },
    {
      "lang": "es",
      "value": "Microsoft Internet Explorer 7 hasta 11 no previenen el uso de certificados EV SSL comodines, lo que podría permitir a atacantes remotos falsificar un nivel de confianza mediante el aprovechamiento de la emisión indebida de un certificado comodín por una autoridad de certificación reconocida, también conocido como 'vulnerabilidad de evasión de la funcionalidad de la seguridad de certificación de validación extendida (EV).'"
    }
  ],
  "lastModified": "2026-06-17T00:07:09.460",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A33FA7F-BB2A-4C66-B608-72997A2BD1DB"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A52E757F-9B41-43B4-9D67-3FEDACA71283"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C043EDDD-41BF-4718-BDCF-158BBBDB6360"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5808661-A082-4CBE-808C-B253972487B4"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:internet_explorer:11:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7809F78-8D56-4925-A8F9-4119B973A667"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}