Junglewise Threat Intelligence

CVE-2013-2551: Microsoft Internet Explorer Use-After-Free Vulnerability

CVE-2013-2551 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-28

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

A use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code. The flaw is triggered when a crafted website causes the browser to access a deleted object in memory.

Affected products

  • Microsoft Internet Explorer 6 through 10

Timeline

  • 2013-03-06: disclosed: Demonstrated by VUPEN during Pwn2Own competition at CanSecWest 2013.
  • 2013-05-14: patched: Microsoft released security bulletin MS13-037 to address the issue.
  • 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats