TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2013-3893

HIGHCISA KEV
8.8

Beschreibung

Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll.

CVE Details

CVSS v3.1 Bewertung8.8
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht9/18/2013
Zuletzt geandert4/22/2026
Quellekev
Honeypot-Sichtungen0

CISA KEV

HerstellerMicrosoft
ProduktInternet Explorer
SchwachstellennameMicrosoft Internet Explorer Resource Management Errors Vulnerability
KEV Aufnahmedatum2025-08-12
Behebungsfrist2025-09-02
Ransomware-NutzungUnknown

Betroffene Produkte

microsoft:internet_explorer

Schwachen (CWE)

CWE-416CWE-416

Referenzen

http://jvn.jp/en/jp/JVN27443259/index.html(af854a3a-2127-422b-91ae-364da2661108)
http://pastebin.com/raw.php?i=Hx1L5gu6(af854a3a-2127-422b-91ae-364da2661108)
http://technet.microsoft.com/security/advisory/2887505(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/62453(af854a3a-2127-422b-91ae-364da2661108)
http://www.us-cert.gov/ncas/alerts/TA13-288A(af854a3a-2127-422b-91ae-364da2661108)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.