⚠ Actively exploited
Added to CISA KEV on 2022-03-03. Federal agencies required to patch by 2022-03-24. Required action: Apply updates per vendor instructions..

CVE-2013-3897Use After Free in Microsoft Internet Explorer

CWE-416Use After FreeCWE-39915 documents10 sources
Severity
8.8HIGHNVD
EPSS
88.2%
top 0.51%
CISA KEV
KEV
Added 2022-03-03
Due 2022-03-24
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedOct 9
KEV addedMar 3
KEV dueMar 24
Latest updateMay 14
CISA Required Action: Apply updates per vendor instructions.

Description

Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability."

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

NVDmicrosoft/internet_explorer6 versions+5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5cv5-x27q-h8hq: Use-after-free vulnerability in the CDisplayPointer class in mshtml2022-05-14
VulnCheck
Microsoft Internet Explorer Use-After-Free Vulnerability2013

💥Exploits & PoCs

2
Exploit-DB
Microsoft Internet Explorer - CDisplayPointer Use-After-Free (MS13-080) (Metasploit)2013-10-15
Metasploit
MS13-080 Microsoft Internet Explorer CDisplayPointer Use-After-Free

📋Vendor Advisories

1
CISA
Microsoft Internet Explorer Use-After-Free Vulnerability2022-03-03

🕵️Threat Intelligence

9
Krebs
Adobe, Microsoft Push Critical Security Fixes2013-10-08
Talos
IE Zero Day CVE-2013-3897 -- You've been protected for more than a week.2013-10-08
Talos
Microsoft Update Tuesday October 2013: Another IE 0-day release2013-10-08
Talos
Microsoft Update Tuesday October 2013: Another IE 0-day release2013-10-08
Talos
IE Zero Day CVE-2013-3897 -- You've been protected for more than a week.2013-10-08
CVE-2013-3897 — Use After Free in Microsoft | cvebase