CVE-2013-5045 EXPLOIT
6.2
MEDIUM · CVSS 2.0 · EPSS 17.4% (pctl 97)
Patch early
A public exploit exists.
Description
Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability."
Scoring
| CVSS | 6.2 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:L/AC:H/Au:N/C:C/I:C/A:C |
| EPSS | 17.39% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2013-12-11 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | internet explorer |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Registry Symlink - IE Sandbox Escape (MS13-097) (Metasploit) | 2014-06-27 |
References
- http://packetstormsecurity.com/files/127245/MS13-097-Registry-Symlink-IE-Sandbox-Escape.html
- http://www.exploit-db.com/exploits/33893
- http://www.osvdb.org/100757
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-097
- http://packetstormsecurity.com/files/127245/MS13-097-Registry-Symlink-IE-Sandbox-Escape.html
- http://www.exploit-db.com/exploits/33893
- http://www.osvdb.org/100757
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-097
→ the Explorer · watch your stack · NVD