CVE-2013-3897
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Internet Explorer Use-After-Free Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability."
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 77% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-416
מוצרים מושפעים
microsoft: internet explorer; microsoft: windows server 2003; microsoft: windows xp; microsoft: windows server 2008; microsoft: windows vista; microsoft: windows 7; microsoft: windows 8; microsoft: windows server 2012; microsoft: windows 8.1; microsoft: windows rt 8.1
קישורים
- http://blogs.technet.com/b/srd/archive/2013/10/08/ms13-080-addresses-two-vulne… Broken LinkVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-… PatchVendor Advisory
- http://blogs.technet.com/b/srd/archive/2013/10/08/ms13-080-addresses-two-vulne… Broken LinkVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-… PatchVendor Advisory
- http://www.us-cert.gov/ncas/alerts/TA13-288A Third Party AdvisoryUS Government Resource
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval… Broken Link
- http://www.us-cert.gov/ncas/alerts/TA13-288A Third Party AdvisoryUS Government Resource
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval… Broken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource