Executive brief
A use-after-free vulnerability exists in the CDisplayPointer class within mshtml.dll in Microsoft Internet Explorer. Remote attackers can execute arbitrary code or cause a denial of service via crafted JavaScript code utilizing the onpropertychange event handler.
Affected products
- Microsoft Internet Explorer 6 through 11
Timeline
- 2013-09: exploited: Exploited in the wild in September and October 2013.
- 2013-10-08: patched: MS13-080 addresses the vulnerability.
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.