Netskope Threat Labs

BROWSER-IE Microsoft Internet Explorer VML use after free attempt

IPS-SWG

1 SID: 30894

First seen
March 2022
Last seen
May 2026

Detects web content that exploits CVE-2014-1776, a use-after-free in Internet Explorer's Vector Markup Language handling that can allow code execution. The rule matches the embedded VML binary structures that public exploits use to free objects while they remain in use, and this flaw saw active exploitation in targeted campaigns.