peter bassill · operator
$ cve CVE-2013-7331 JSON

CVE-2013-7331 KEV

6.5
MEDIUM · CVSS 3.1 · EPSS 50.2% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-15.

Description

The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a res:// URL, and exploited in the wild in February 2014.

Scoring

CVSS6.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
EPSS50.21% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-209
On CISA KEVyes — remediate by 2022-06-15
Public exploitnone known
Published2014-02-26
Last modified2026-06-17

CISA KEV

NameMicrosoft Internet Explorer Information Disclosure Vulnerability
Added2022-05-25
Due2022-06-15
Vendor / productMicrosoft / Internet Explorer
Ransomware usenone reported

Affected (10)

VendorProduct
microsoftinternet explorer
microsoftwindows 7
microsoftwindows 8
microsoftwindows 8.1
microsoftwindows rt
microsoftwindows rt 8.1
microsoftwindows server 2003
microsoftwindows server 2008
microsoftwindows server 2012
microsoftwindows vista

References

→ the Explorer  ·  watch your stack  ·  NVD