CVE-2013-1347 KEV EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 77.7% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-03-24.
Description
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 77.74% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-416 |
| On CISA KEV | yes — remediate by 2022-03-24 |
| Public exploit | yes |
| Published | 2013-05-05 |
| Last modified | 2026-06-16 |
CISA KEV
| Name | Microsoft Internet Explorer Remote Code Execution Vulnerability |
|---|---|
| Added | 2022-03-03 |
| Due | 2022-03-24 |
| Vendor / product | Microsoft / Internet Explorer |
| Ransomware use | none reported |
Affected (6)
| Vendor | Product |
|---|---|
| microsoft | internet explorer |
| microsoft | windows 7 |
| microsoft | windows server 2003 |
| microsoft | windows server 2008 |
| microsoft | windows vista |
| microsoft | windows xp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Internet Explorer - CGenericElement Object Use-After-Free (Metasploit) | 2013-05-07 |
References
- http://technet.microsoft.com/security/advisory/2847140
- http://www.exploit-db.com/exploits/25294
- http://www.us-cert.gov/ncas/alerts/TA13-134A
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-038
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16727
- http://technet.microsoft.com/security/advisory/2847140
- http://www.exploit-db.com/exploits/25294
- http://www.us-cert.gov/ncas/alerts/TA13-134A
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-038
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16727
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-1347
→ the Explorer · watch your stack · NVD