CVE-2013-2551highunder attackransomwareCWE-416

CVE-2013-2551

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 8.8epss 74%
from disclosure to weapon94 days
Published on NVDMar 11
1st PoC+94d
metasploitMar 6
CISA KEV+3304d
exploitation probability
74%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-04-18

Apply updates per vendor instructions.

In short

Internet Explorer versions 6-10 have a flaw where the browser can access memory that has been freed, allowing attackers to run malicious code through a specially crafted website. This happens because the browser doesn't properly track when an object is deleted.

Technical detail

Use-after-free vulnerability in MSHTML engine affecting IE 6-10; remote attacker can craft HTML/JavaScript that triggers dereferencing of freed memory objects, leading to code execution in the browser context. Requires user to visit malicious website; no authentication or user interaction beyond visiting the site needed.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-1309.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.