TROYANOSYVIRUS
Volver a CVEs

CVE-2013-3893

HIGHCISA KEV
8.8

Descripcion

Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll.

Detalles CVE

Puntuacion CVSS v3.18.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado9/18/2013
Ultima modificacion4/22/2026
Fuentekev
Avistamientos honeypot0

CISA KEV

VendedorMicrosoft
ProductoInternet Explorer
Nombre vulnerabilidadMicrosoft Internet Explorer Resource Management Errors Vulnerability
Fecha inclusion KEV2025-08-12
Fecha limite remediacion2025-09-02
Uso en ransomwareUnknown

Productos afectados

microsoft:internet_explorer

Debilidades (CWE)

CWE-416CWE-416

Referencias

http://jvn.jp/en/jp/JVN27443259/index.html(af854a3a-2127-422b-91ae-364da2661108)
http://pastebin.com/raw.php?i=Hx1L5gu6(af854a3a-2127-422b-91ae-364da2661108)
http://technet.microsoft.com/security/advisory/2887505(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/62453(af854a3a-2127-422b-91ae-364da2661108)
http://www.us-cert.gov/ncas/alerts/TA13-288A(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.