My customer's IPS is stating an security issue on the riskminder-client.js file. the IPS warning stating: "HTTP: Microsoft Internet Explorer Onproperychnage use after free vulnerability (CVE-2014-0312)"
We need a quick response about this CVE and if a mitigation is required.
Environment
Riskminder 3.1
Resolution
The vulnerabilities mentioned here do not look like an issue with the client but are specific to Microsoft Internet Explorer. Microsoft has mentioned that whoever is facing this vulnerability has to install the update mentioned in the link below. https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2014/ms14-012
The updates have been mentioned for each particular vulnerability and both CVE-2014-0312 and CVE-2014-0324 are mentioned there.