Junglewise Threat Intelligence

CVE-2013-3897: Microsoft Internet Explorer Use-After-Free Vulnerability

CVE-2013-3897 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-03

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

A use-after-free vulnerability exists in the CDisplayPointer class within mshtml.dll in Microsoft Internet Explorer. Remote attackers can execute arbitrary code or cause a denial of service via crafted JavaScript code utilizing the onpropertychange event handler.

Affected products

  • Microsoft Internet Explorer 6 through 11

Timeline

  • 2013-09: exploited: Exploited in the wild in September and October 2013.
  • 2013-10-08: patched: MS13-080 addresses the vulnerability.
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats