CVE-2013-2551
KEV ransomwaremassUse-After-Free RCE in Microsoft Internet Explorer
CISA: Microsoft Internet Explorer Use-After-Free Vulnerability
CVE-2013-2551 is a use-after-free memory corruption flaw (CWE-416) in Microsoft Internet Explorer. An attacker triggers it by luring a user to a crafted website that causes the browser to access an object that has already been deleted from memory. Successful exploitation allows the attacker to execute arbitrary code on the victim machine, typically in the context of the logged-in user. All Internet Explorer deployments are potentially affected; the source data does not specify version ranges, but the flaw is best known as a long-lived legacy-browser issue exploited by drive-by exploit kits. The vulnerability is confirmed to be exploited in the wild: it is listed in CISA KEV (added 2022-03-28) with known ransomware use, and EPSS assigns it a 74.1% probability of exploitation in the next 30 days (99th percentile).
What to do: Apply Microsoft updates for Internet Explorer per vendor instructions, as required by the CISA KEV listing, prioritizing any Windows systems still using IE or IE-based components. As interim mitigation, restrict browsing to trusted sites and ensure users are not running as administrators for routine web activity. Audit legacy environments for obsolete IE usage and migrate those systems to a supported, actively patched browser where updates are no longer feasible.
| Microsoft Internet Explorer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.
- Affected
- Microsoft Internet Explorer
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- Microsoft
- Products
- Internet Explorer
- Weakness
- CWE-416