Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2013-4015Microsoft Internet Explorer vulnerability

CWE-2643 documents3 sources
Severity
6.9MEDIUMNVD
EPSS
4.4%
top 10.97%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJul 26
Latest updateMay 14

Description

Microsoft Internet Explorer 6 through 10 allows local users to bypass the elevation policy check in the (1) Protected Mode or (2) Enhanced Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages1 packages

NVDmicrosoft/internet_explorer5 versions+4

🔴Vulnerability Details

1
GHSA
GHSA-wx27-qc7w-cv7c: Microsoft Internet Explorer 6 through 10 allows local users to bypass the elevation policy check in the (1) Protected Mode or (2) Enhanced Protected M2022-05-14

💥Exploits & PoCs

1
Exploit-DB
Microsoft Internet Explorer - CAnchorElement Use-After-Free (MS13-055) (Metasploit)2013-09-10
CVE-2013-4015 — Microsoft vulnerability | cvebase