CVE-2013-3163
KEVmassRemote Code Execution via Memory Corruption in Microsoft Internet Explorer
CISA: Microsoft Internet Explorer Memory Corruption Vulnerability
Internet Explorer is affected by a memory corruption vulnerability (mapped by CISA to CWE-94) that can be triggered when the browser processes specially crafted web content, allowing remote attackers to execute code or cause a denial of service. An attacker typically triggers the flaw by luring a user to visit an attacker-crafted or compromised website that corrupts browser memory during processing. Successful exploitation can give the attacker code execution in the context of the current user, with a browser or system crash as an alternative outcome. Those affected are users of legacy, end-of-life Microsoft Internet Explorer on Windows, which CISA's required action explicitly flags as an EOL product that should be disconnected if still in use. Exploitation is confirmed: CISA added CVE-2013-3163 to the Known Exploited Vulnerabilities catalog on 2023-03-30 (in the KEV update tied to bugs used by commercial surveillance spyware), EPSS assigns a 70.7% probability of exploitation within 30 days (99th percentile), ransomware use is unknown, and no public proof-of-concept is known.
What to do: Because the impacted product is end-of-life, follow CISA's required action: inventory and retire or disconnect Internet Explorer wherever it is still in use, migrating users to Microsoft Edge (using Edge IE mode where legacy apps require it). If a still-supported legacy OS must keep standalone IE, confirm the June 2013 cumulative Internet Explorer update (MS13-047) or later patches are applied and restrict IE to trusted sites. Given confirmed in-the-wild exploitation and EPSS of ~71%, prioritize remediation of any remaining EOL IE deployments and hunt for anomalous browser crash or child-process activity.
| Microsoft Internet Explorer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website.
- Affected
- Microsoft Internet Explorer
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Internet Explorer
- Weakness
- CWE-94