ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Microsoft Updates October 2013

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2013-3893
Memory Corruption RCE in Microsoft Internet Explorer

CVE-2013-3893 is a resource-management (memory corruption) flaw in Microsoft Internet Explorer that can allow remote code execution (CWE-399). It is triggered remotely, typically when a user views attacker-controlled web content in a vulnerable version of Internet Explorer. A successful attacker gains the ability to execute arbitrary code in the context of the current user, potentially compromising the workstation. Organizations still running Internet Explorer, which CISA notes may be end-of-life (EoL) and/or end-of-service (EoS), are affected; specific affected version ranges were not provided in the source data. The flaw was patched in Microsoft's October 2013 Patch Tuesday after being exploited in the wild (Operation DeputyDog, per related reporting), and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-08-12 with a very high EPSS of 85.9% (100th percentile), indicating active or imminent exploitation.

Do: Apply mitigations per Microsoft's vendor instructions and follow applicable BOD 22-01 guidance for cloud services, or discontinue use of Internet Explorer if mitigations are unavailable, per CISA's required action. Verify that affected systems have the October 2013 Patch Tuesday (or later) cumulative Internet Explorer security updates installed, and audit your estate for remaining legacy IE usage. Where IE is still needed for legacy sites, migrate to Microsoft Edge with IE mode and treat in-the-wild exploitation as likely given the KEV listing and 85.9% EPSS.

86% KEV
  • Microsoft Internet Explorer
masstens to hundreds of millions of legacy Windows devices historically capable of running IE; current actively used legacy IE installs unknown but plausibly in…
CVE-2013-3897
Use-After-Free RCE in Microsoft Internet Explorer (CVE-2013-3897)

CVE-2013-3897 is a use-after-free vulnerability in the CDisplayPointer component of Microsoft Internet Explorer that enables remote code execution when a user views attacker-controlled web content. It is triggered by luring a user to a malicious or compromised webpage where Internet Explorer references memory that has already been freed, allowing the attacker to corrupt memory and execute arbitrary code with the rights of the logged-on user. Any user or organization browsing with Internet Explorer on Windows was exposed; the flaw was fixed in Microsoft's October 2013 Patch Tuesday cumulative IE security updates, and because Internet Explorer is now retired, remaining exposure sits on legacy Windows estates and IE-dependent legacy web applications. Exploitation is confirmed: the bug was exploited as a zero-day in targeted attacks when disclosed in late September 2013, it is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03; ransomware use unknown), and EPSS estimates a 77.5% probability of exploitation within 30 days (100th percentile). No public proof-of-concept exploit is documented in the source data, but confirmed in-the-wild use makes patching or browser migration urgent.

Do: Apply Microsoft's October 2013 Patch Tuesday cumulative Internet Explorer security update (MS13-080) per vendor/CISA instructions, prioritizing internet-facing and legacy Windows hosts where IE is still used for browsing or legacy web applications. Because IE is retired and no longer receives security fixes, migrate any remaining IE-dependent users to a supported modern browser and hunt for indicators of the historical in-the-wild exploitation. Ransomware use is unknown per the KEV entry and no public PoC is available, so treat patching and migration, not signature detection, as the primary control.

77% KEV
  • Microsoft Internet Explorer
masshundreds of millions of legacy Windows systems with Internet Explorer historically (IE shipped with essentially every Windows PC); current active exposure is…
Full article459 words · extracted from securelist.com · click to collapse

Software

Software

08 Oct 2013

minute read

Older Versions of Internet Explorer, Office, Silverlight become Ghastly, Ghoulish Treehouse of Horrors

Microsoft’s 2013 Treehouse of Horror Bulletins include a long list of fixes for memory corruption vulnerabilities effecting mostly previous versions of the software, and not the latest versions. Of immediate interest to most Windows users are the critical vulnerabilities being patched in Internet Explorer, multiple Windows drivers, and the .Net Framework which even effects the latest versions of Windows 8 and Windows Server 2012. Systems administrators at organizations also may pay immediate attention to the critical vulnerabilities in the Windows Common Control Library patched by MS13-083, which enables server side ASP.NET webapp exploitation on 64 bit systems. MS13-080 through MS13-087 include four Bulletins rated critical and four Bulletins rated Important addressing 26 vulnerabilities.

Much of the list of ghoulish October Bulletins appears to be similar to September’s list, but the news of note this month is that the Internet Explorer vulnerabilities CVE-2013-3893 and CVE-2013-3897 are being exploited as a part of targeted attacks. We have been monitoring the situation in Japan and southeastern asia, where attackers have been using exploits that succesfully pop Internet Explorer versions 8 and 9.

It’s somewhat surprising that the Office vulnerabilities effecting Office 2003 and 2007 are only being rated “important” this month being patched with MS13-084, MS13-085, and MS13-086, considering that Microsoft Excel and Word have been leading vectors of spearphishing attacks for the past year or so. The vulnerabilities enable remote code execution on systems where the user is duped into opening the attachment.

Interesting and unusual is this month’s Windows Common Control Library vulnerability effecting only x64 ASP.NET web applications. Attackers may send a pre-authentication web request to web applications attacking integer overflow vulnerability CVE-2013-3195 enabling remote code execution. System admins following best practices may end up with process running on their web servers with local user rights.

Full ghastly October Bulletin details on Microsoft’s site here. Microsoft’s Update software is a convenient and easy way to update your system software every month. If you are running Microsoft software, please go ahead and do so now.208193615

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/microsoft-updates-october-2013/57321/