TROYANOSYVIRUS
Voltar para CVEs

CVE-2013-3893

HIGHCISA KEV
8.8

Descricao

Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll.

Detalhes CVE

Pontuacao CVSS v3.18.8
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioREQUIRED
Publicado9/18/2013
Ultima modificacao4/22/2026
Fontekev
Avistamentos honeypot0

CISA KEV

FornecedorMicrosoft
ProdutoInternet Explorer
Nome da vulnerabilidadeMicrosoft Internet Explorer Resource Management Errors Vulnerability
Data inclusao KEV2025-08-12
Prazo de remediacao2025-09-02
Uso em ransomwareUnknown

Produtos afetados

microsoft:internet_explorer

Fraquezas (CWE)

CWE-416CWE-416

Referencias

http://jvn.jp/en/jp/JVN27443259/index.html(af854a3a-2127-422b-91ae-364da2661108)
http://pastebin.com/raw.php?i=Hx1L5gu6(af854a3a-2127-422b-91ae-364da2661108)
http://technet.microsoft.com/security/advisory/2887505(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/62453(af854a3a-2127-422b-91ae-364da2661108)
http://www.us-cert.gov/ncas/alerts/TA13-288A(af854a3a-2127-422b-91ae-364da2661108)

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.