peter bassill · operator
$ cve CVE-2013-4015 JSON

CVE-2013-4015 EXPLOIT

6.9
MEDIUM · CVSS 2.0 · EPSS 2.8% (pctl 86)

Patch early

A public exploit exists.

Description

Microsoft Internet Explorer 6 through 10 allows local users to bypass the elevation policy check in the (1) Protected Mode or (2) Enhanced Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code.

Scoring

CVSS6.9 (MEDIUM, v2.0)
VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS2.82% — more likely to be exploited than 86% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2013-07-26
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftinternet explorer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD