Junglewise Threat Intelligence

CVE-2013-3163: Microsoft Internet Explorer Memory Corruption Vulnerability

CVE-2013-3163 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-03-30

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

Microsoft Internet Explorer 8 through 10 contains a memory corruption vulnerability (out-of-bounds write) that allows remote attackers to execute arbitrary code or cause a denial of service via a crafted website. The vulnerability is actively exploited in the wild and is tracked in CISA's Known Exploited Vulnerabilities Catalog.

Affected products

  • Microsoft Internet Explorer 8 through 10

Timeline

  • 2013-07-09: patched: Microsoft Security Bulletin MS13-055 released.
  • 2023-03-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2023-03-30: disclosed

Related threats