Executive brief
A use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code. The flaw is triggered when a crafted website causes the browser to access a CDwnBindInfo object that was either improperly allocated or previously deleted.
Affected products
- Microsoft Internet Explorer 6 through 8
Timeline
- 2012-12: exploited: Exploited in the wild in December 2012.
- 2012-12-29: disclosed: Initial public reports of the zero-day vulnerability.
- 2012-12-31: patched: Microsoft released a 'Fix it' solution.
- 2013-01-14: patched: Official security bulletin MS13-008 released.
- 2024-07-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.