Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014.
https://blogs.cisco.com/security/talos/opening-zxshell
http://blogs.cisco.com/security/talos/threat-spotlight-group-72
https://www.dropbox.com/s/pyxjgycmudirbqe/CVE-2014-0322.zip
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0322
https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-0360
http://twitter.com/nanoc0re/statuses/434251658344673281