← לוח פגיעויות

CVE-2013-3897

גבוהה 8.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Microsoft Internet Explorer Use-After-Free Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability."

מדדים

CVSS 3.1
8.8 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
77% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-416

מוצרים מושפעים

microsoft: internet explorer; microsoft: windows server 2003; microsoft: windows xp; microsoft: windows server 2008; microsoft: windows vista; microsoft: windows 7; microsoft: windows 8; microsoft: windows server 2012; microsoft: windows 8.1; microsoft: windows rt 8.1

קישורים