CVE-2013-1347
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Internet Explorer Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 78% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-416
מוצרים מושפעים
microsoft: internet explorer; microsoft: windows 7; microsoft: windows server 2003; microsoft: windows server 2008; microsoft: windows vista; microsoft: windows xp
קישורים
- http://technet.microsoft.com/security/advisory/2847140 MitigationPatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-… PatchVendor Advisory
- http://technet.microsoft.com/security/advisory/2847140 MitigationPatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-… PatchVendor Advisory
- http://www.exploit-db.com/exploits/25294 ExploitThird Party AdvisoryVDB Entry
- http://www.exploit-db.com/exploits/25294 ExploitThird Party AdvisoryVDB Entry
- http://www.us-cert.gov/ncas/alerts/TA13-134A Third Party AdvisoryUS Government Resource
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval… Broken Link
- http://www.us-cert.gov/ncas/alerts/TA13-134A Third Party AdvisoryUS Government Resource
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval… Broken Link