ZeroHour

CVE-2013-3163

KEVmass

Remote Code Execution via Memory Corruption in Microsoft Internet Explorer

CISA: Microsoft Internet Explorer Memory Corruption Vulnerability

CVSS
EPSS
71%p99
Published
KEV added
AI analysis

Internet Explorer is affected by a memory corruption vulnerability (mapped by CISA to CWE-94) that can be triggered when the browser processes specially crafted web content, allowing remote attackers to execute code or cause a denial of service. An attacker typically triggers the flaw by luring a user to visit an attacker-crafted or compromised website that corrupts browser memory during processing. Successful exploitation can give the attacker code execution in the context of the current user, with a browser or system crash as an alternative outcome. Those affected are users of legacy, end-of-life Microsoft Internet Explorer on Windows, which CISA's required action explicitly flags as an EOL product that should be disconnected if still in use. Exploitation is confirmed: CISA added CVE-2013-3163 to the Known Exploited Vulnerabilities catalog on 2023-03-30 (in the KEV update tied to bugs used by commercial surveillance spyware), EPSS assigns a 70.7% probability of exploitation within 30 days (99th percentile), ransomware use is unknown, and no public proof-of-concept is known.

What to do: Because the impacted product is end-of-life, follow CISA's required action: inventory and retire or disconnect Internet Explorer wherever it is still in use, migrating users to Microsoft Edge (using Edge IE mode where legacy apps require it). If a still-supported legacy OS must keep standalone IE, confirm the June 2013 cumulative Internet Explorer update (MS13-047) or later patches are applied and restrict IE to trusted sites. Given confirmed in-the-wild exploitation and EPSS of ~71%, prioritize remediation of any remaining EOL IE deployments and hunt for anomalous browser crash or child-process activity.

Affected
Microsoft Internet Explorer
Estimated exposure
masshundreds of millions of legacy Windows devices able to run IE (historical default Windows browser; active exposure now far lower post-2022 EOL) — Internet Explorer shipped as the default Windows browser for roughly two decades, so legacy Windows estates of hundreds of millions of devices could run it, but precise current exposure is unknown because the browser is end-of-life and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website.

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Internet Explorer
Weakness
CWE-94

In the news