CVE-2013-3897
KEVmassUse-After-Free RCE in Microsoft Internet Explorer (CVE-2013-3897)
CISA: Microsoft Internet Explorer Use-After-Free Vulnerability
CVE-2013-3897 is a use-after-free vulnerability in the CDisplayPointer component of Microsoft Internet Explorer that enables remote code execution when a user views attacker-controlled web content. It is triggered by luring a user to a malicious or compromised webpage where Internet Explorer references memory that has already been freed, allowing the attacker to corrupt memory and execute arbitrary code with the rights of the logged-on user. Any user or organization browsing with Internet Explorer on Windows was exposed; the flaw was fixed in Microsoft's October 2013 Patch Tuesday cumulative IE security updates, and because Internet Explorer is now retired, remaining exposure sits on legacy Windows estates and IE-dependent legacy web applications. Exploitation is confirmed: the bug was exploited as a zero-day in targeted attacks when disclosed in late September 2013, it is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03; ransomware use unknown), and EPSS estimates a 77.5% probability of exploitation within 30 days (100th percentile). No public proof-of-concept exploit is documented in the source data, but confirmed in-the-wild use makes patching or browser migration urgent.
What to do: Apply Microsoft's October 2013 Patch Tuesday cumulative Internet Explorer security update (MS13-080) per vendor/CISA instructions, prioritizing internet-facing and legacy Windows hosts where IE is still used for browsing or legacy web applications. Because IE is retired and no longer receives security fixes, migrate any remaining IE-dependent users to a supported modern browser and hunt for indicators of the historical in-the-wild exploitation. Ransomware use is unknown per the KEV entry and no public PoC is available, so treat patching and migration, not signature detection, as the primary control.
| Microsoft Internet Explorer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code.
- Affected
- Microsoft Internet Explorer
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Internet Explorer
- Weakness
- CWE-399