CVE-2013-3897 KEV EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 77.3% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-03-24.
Description
Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability."
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 77.31% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-416 |
| On CISA KEV | yes — remediate by 2022-03-24 |
| Public exploit | yes |
| Published | 2013-10-09 |
| Last modified | 2026-06-16 |
CISA KEV
| Name | Microsoft Internet Explorer Use-After-Free Vulnerability |
|---|---|
| Added | 2022-03-03 |
| Due | 2022-03-24 |
| Vendor / product | Microsoft / Internet Explorer |
| Ransomware use | none reported |
Affected (10)
| Vendor | Product |
|---|---|
| microsoft | internet explorer |
| microsoft | windows 7 |
| microsoft | windows 8 |
| microsoft | windows 8.1 |
| microsoft | windows rt 8.1 |
| microsoft | windows server 2003 |
| microsoft | windows server 2008 |
| microsoft | windows server 2012 |
| microsoft | windows vista |
| microsoft | windows xp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Internet Explorer - CDisplayPointer Use-After-Free (MS13-080) (Metasploit) | 2013-10-15 |
References
- http://blogs.technet.com/b/srd/archive/2013/10/08/ms13-080-addresses-two-vulnerabilities-under-limited-targeted-attacks.aspx
- http://www.us-cert.gov/ncas/alerts/TA13-288A
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-080
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18989
- http://blogs.technet.com/b/srd/archive/2013/10/08/ms13-080-addresses-two-vulnerabilities-under-limited-targeted-attacks.aspx
- http://www.us-cert.gov/ncas/alerts/TA13-288A
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-080
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18989
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-3897
→ the Explorer · watch your stack · NVD