Junglewise Threat Intelligence

CVE-2013-7331: Microsoft Internet Explorer Information Disclosure Vulnerability

CVE-2013-7331 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2022-05-25

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

The Microsoft.XMLDOM ActiveX control in Internet Explorer allows remote attackers to determine the existence of local pathnames, UNC shares, and intranet network information via error code analysis. This information disclosure vulnerability can be used to detect anti-malware applications or map internal networks.

Affected products

  • Microsoft Internet Explorer 6, 7, 8, 9, 10, 11
  • Microsoft Microsoft.XMLDOM ActiveX control Windows 8.1 and earlier

Timeline

  • 2013-04-01: disclosed: Initial public disclosure of the XMLDOM information leak technique.
  • 2014-02-01: exploited: Exploited in the wild in February 2014 (Operation Snowman).
  • 2014-09-09: patched: Microsoft released MS14-052 to address the issue.
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats