Executive brief
A use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code. The flaw is triggered when a crafted website causes the browser to access a deleted object in memory.
Affected products
- Microsoft Internet Explorer 6 through 10
Timeline
- 2013-03-06: disclosed: Demonstrated by VUPEN during Pwn2Own competition at CanSecWest 2013.
- 2013-05-14: patched: Microsoft released security bulletin MS13-037 to address the issue.
- 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.