TROYANOSYVIRUS
Retour aux CVEs

CVE-2013-3893

HIGHCISA KEV
8.8

Description

Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll.

Details CVE

Score CVSS v3.18.8
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurREQUIRED
Publie9/18/2013
Derniere modification4/22/2026
Sourcekev
Observations honeypot0

CISA KEV

FournisseurMicrosoft
ProduitInternet Explorer
Nom vulnerabiliteMicrosoft Internet Explorer Resource Management Errors Vulnerability
Date ajout KEV2025-08-12
Date limite remediation2025-09-02
Utilise dans ransomwareUnknown

Produits affectes

microsoft:internet_explorer

Faiblesses (CWE)

CWE-416CWE-416

References

http://jvn.jp/en/jp/JVN27443259/index.html(af854a3a-2127-422b-91ae-364da2661108)
http://pastebin.com/raw.php?i=Hx1L5gu6(af854a3a-2127-422b-91ae-364da2661108)
http://technet.microsoft.com/security/advisory/2887505(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/62453(af854a3a-2127-422b-91ae-364da2661108)
http://www.us-cert.gov/ncas/alerts/TA13-288A(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.