ZeroHour

CVE-2013-7331

KEVmass

Information Disclosure in Microsoft Internet Explorer Lets Pages Detect Anti-Malware

CISA: Microsoft Internet Explorer Information Disclosure Vulnerability

CVSS
EPSS
58%p99
Published
KEV added
AI analysis

CVE-2013-7331 is an information disclosure flaw (CWE-200) in Microsoft Internet Explorer in which resources loaded into memory can be queried by web content. An attacker triggers it by luring a user to a malicious or compromised webpage whose crafted script probes memory-resident resources, requiring no authentication and no interaction beyond ordinary browsing. What the attacker gains is knowledge of which anti-malware applications are installed on the victim, information commonly used for victim fingerprinting; related coverage of the Nuclear exploit kit reflects how exploit kits leveraged this kind of security-product detection to tailor or withhold follow-on exploits. Any Microsoft Internet Explorer deployment is affected; the provided data does not specify exact version ranges, and the flaw was addressed in Microsoft's significant September 2014 Internet Explorer security bulletin. Exploitation is confirmed in the wild: the flaw was added to the CISA KEV catalog on 2022-05-25 with a high EPSS of 58% (99th percentile), though ransomware association is listed as unknown and no public proof-of-concept is known.

What to do: Apply Microsoft's September 2014 Internet Explorer security updates (or any later cumulative IE updates) per vendor instructions, as required by the CISA KEV catalog, and audit for Windows systems still running unpatched IE builds. Prioritize general-purpose browsing and internet-facing endpoints since the flaw is used to fingerprint victims, and migrate any remaining legacy Internet Explorer usage to a supported browser such as Microsoft Edge (with IE mode for legacy dependencies).

Affected
Microsoft Internet Explorer
Estimated exposure
masshundreds of millions of Windows devices with Internet Explorer installed — Internet Explorer shipped as the default browser with essentially all mainstream Windows versions during the affected period, so the plausibly affected installed base is bounded by the very large Windows desktop population, with actual…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware applications.

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Internet Explorer
Weakness
CWE-200

In the news