CVE-2013-4015 EXPLOIT
6.9
MEDIUM · CVSS 2.0 · EPSS 2.8% (pctl 86)
Patch early
A public exploit exists.
Description
Microsoft Internet Explorer 6 through 10 allows local users to bypass the elevation policy check in the (1) Protected Mode or (2) Enhanced Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code.
Scoring
| CVSS | 6.9 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 2.82% — more likely to be exploited than 86% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-07-26 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | internet explorer |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Internet Explorer - CAnchorElement Use-After-Free (MS13-055) (Metasploit) | 2013-09-10 |
References
→ the Explorer · watch your stack · NVD