CVE-2013-3893
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Internet Explorer Resource Management Errors Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 86% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-416
מוצרים מושפעים
microsoft: internet explorer
קישורים
- http://blogs.technet.com/b/srd/archive/2013/10/08/ms13-080-addresses-two-vulne… Vendor Advisory
- http://technet.microsoft.com/security/advisory/2887505 Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-… Vendor Advisory
- http://blogs.technet.com/b/srd/archive/2013/10/08/ms13-080-addresses-two-vulne… Vendor Advisory
- http://technet.microsoft.com/security/advisory/2887505 Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-… Vendor Advisory
- http://blogs.technet.com/b/srd/archive/2013/09/17/cve-2013-3893-fix-it-workaro… Exploit
- http://packetstormsecurity.com/files/162585/Microsoft-Internet-Explorer-8-SetM… Exploit
- http://pastebin.com/raw.php?i=Hx1L5gu6 Exploit
- http://blogs.technet.com/b/srd/archive/2013/09/17/cve-2013-3893-fix-it-workaro… Exploit