ZeroHour

CVE-2013-1347

KEVmass

Memory corruption RCE in Microsoft Internet Explorer

CISA: Microsoft Internet Explorer Remote Code Execution Vulnerability

CVSS
EPSS
78%p100
Published
KEV added
AI analysis

CVE-2013-1347 is a memory-corruption vulnerability in Microsoft Internet Explorer (listed under CWE-94, code injection) that corrupts memory in a way that allows an attacker to execute arbitrary code in the security context of the logged-on user. The flaw is triggered remotely through Internet Explorer, typically by luring a user to attacker-controlled web content; related threat-intelligence coverage ties it to the LightsOut Exploit Kit used in APT28 (Pawn Storm) campaigns and to Microsoft's Update Tuesday release for IE 8. Successful exploitation yields code execution with the current user's privileges, meaning full system compromise on accounts with administrative rights. Any environment where users browse with the affected Internet Explorer versions is exposed — CISA lists 'Microsoft Internet Explorer' without enumerating a version range, while related vendor coverage highlights an IE 8 update, putting legacy Windows estates still running IE 8-era browsers at highest risk. Exploitation is confirmed in the wild: the CVE was added to CISA KEV on 2022-03-03 and carries a 77.9% EPSS (100th percentile), although ransomware use is unknown and no standalone public PoC is listed.

What to do: Apply Microsoft's Internet Explorer updates per vendor instructions (the CISA-required action), prioritizing this KEV-listed vulnerability. Inventory legacy Windows systems still running IE 8-era browsers and either migrate those users to a supported browser or restrict untrusted web browsing from those systems, since this is a drive-by browser exploit that executes with the current user's privileges. Verify patch levels across all IE versions in the estate rather than assuming updates propagated.

Affected
Microsoft Internet Explorer
Estimated exposure
mass≈ hundreds of millions of endpoints/users at the time of disclosure, with residual exposure concentrated in legacy IE 8-era estates today — Estimated from 2013 browser-usage data in which IE 8 alone accounted for roughly a third of global browser share and IE was the default browser on Windows, making this the largest single exposed browser cohort at disclosure; current…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer.

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Internet Explorer
Weakness
CWE-94

In the news