CVE-2013-3163highunder attackCWE-787

CVE-2013-3163

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 8.8epss 71%
from disclosure to weapon62 days
Published on NVDJul 10
1st PoC+62d
metasploitJul 9
CISA KEV+3550d
exploitation probability
71%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2023-04-20

The impacted product is end-of-life and should be disconnected if still in use.

In short

Internet Explorer 8-10 can crash or run malicious code when you visit a specially designed website. This happens because the browser doesn't properly manage its memory, allowing attackers to take control of your computer.

Technical detail

Remote code execution or denial of service vulnerability in Internet Explorer 8-10 via memory corruption. Attack vector is network-based through a crafted web page; no user interaction beyond visiting the site is required. Successful exploitation can lead to arbitrary code execution with user privileges or application crash.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and CVE-2013-3151.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.