CVE-2013-1347
KEVmassMemory corruption RCE in Microsoft Internet Explorer
CISA: Microsoft Internet Explorer Remote Code Execution Vulnerability
CVE-2013-1347 is a memory-corruption vulnerability in Microsoft Internet Explorer (listed under CWE-94, code injection) that corrupts memory in a way that allows an attacker to execute arbitrary code in the security context of the logged-on user. The flaw is triggered remotely through Internet Explorer, typically by luring a user to attacker-controlled web content; related threat-intelligence coverage ties it to the LightsOut Exploit Kit used in APT28 (Pawn Storm) campaigns and to Microsoft's Update Tuesday release for IE 8. Successful exploitation yields code execution with the current user's privileges, meaning full system compromise on accounts with administrative rights. Any environment where users browse with the affected Internet Explorer versions is exposed — CISA lists 'Microsoft Internet Explorer' without enumerating a version range, while related vendor coverage highlights an IE 8 update, putting legacy Windows estates still running IE 8-era browsers at highest risk. Exploitation is confirmed in the wild: the CVE was added to CISA KEV on 2022-03-03 and carries a 77.9% EPSS (100th percentile), although ransomware use is unknown and no standalone public PoC is listed.
What to do: Apply Microsoft's Internet Explorer updates per vendor instructions (the CISA-required action), prioritizing this KEV-listed vulnerability. Inventory legacy Windows systems still running IE 8-era browsers and either migrate those users to a supported browser or restrict untrusted web browsing from those systems, since this is a drive-by browser exploit that executes with the current user's privileges. Verify patch levels across all IE versions in the estate rather than assuming updates propagated.
| Microsoft Internet Explorer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer.
- Affected
- Microsoft Internet Explorer
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Internet Explorer
- Weakness
- CWE-94