ZeroHour

CVE-2013-3897

KEVmass

Use-After-Free RCE in Microsoft Internet Explorer (CVE-2013-3897)

CISA: Microsoft Internet Explorer Use-After-Free Vulnerability

CVSS
EPSS
77%p100
Published
KEV added
AI analysis

CVE-2013-3897 is a use-after-free vulnerability in the CDisplayPointer component of Microsoft Internet Explorer that enables remote code execution when a user views attacker-controlled web content. It is triggered by luring a user to a malicious or compromised webpage where Internet Explorer references memory that has already been freed, allowing the attacker to corrupt memory and execute arbitrary code with the rights of the logged-on user. Any user or organization browsing with Internet Explorer on Windows was exposed; the flaw was fixed in Microsoft's October 2013 Patch Tuesday cumulative IE security updates, and because Internet Explorer is now retired, remaining exposure sits on legacy Windows estates and IE-dependent legacy web applications. Exploitation is confirmed: the bug was exploited as a zero-day in targeted attacks when disclosed in late September 2013, it is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03; ransomware use unknown), and EPSS estimates a 77.5% probability of exploitation within 30 days (100th percentile). No public proof-of-concept exploit is documented in the source data, but confirmed in-the-wild use makes patching or browser migration urgent.

What to do: Apply Microsoft's October 2013 Patch Tuesday cumulative Internet Explorer security update (MS13-080) per vendor/CISA instructions, prioritizing internet-facing and legacy Windows hosts where IE is still used for browsing or legacy web applications. Because IE is retired and no longer receives security fixes, migrate any remaining IE-dependent users to a supported modern browser and hunt for indicators of the historical in-the-wild exploitation. Ransomware use is unknown per the KEV entry and no public PoC is available, so treat patching and migration, not signature detection, as the primary control.

Affected
Microsoft Internet Explorer
Estimated exposure
masshundreds of millions of legacy Windows systems with Internet Explorer historically (IE shipped with essentially every Windows PC); current active exposure is… — Internet Explorer was the default browser bundled with all supported Windows versions at the time, implying an installed base in the hundreds of millions, but Microsoft retired IE in 2022, so present-day active exposure is concentrated on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code.

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Internet Explorer
Weakness
CWE-399

In the news