CVE-2013-3163
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
The impacted product is end-of-life and should be disconnected if still in use.
Internet Explorer 8-10 can crash or run malicious code when you visit a specially designed website. This happens because the browser doesn't properly manage its memory, allowing attackers to take control of your computer.
Remote code execution or denial of service vulnerability in Internet Explorer 8-10 via memory corruption. Attack vector is network-based through a crafted web page; no user interaction beyond visiting the site is required. Successful exploitation can lead to arbitrary code execution with user privileges or application crash.
The full analysis of this CVE is available in Portuguese →