CVE-2013-0029

Description

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka Internet Explorer CHTML Use After Free Vulnerability.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
54.129

Associated Vulnerability

VulnerabilityOS Platform
Cumulative Security Update for Internet Explorer for Windows XP (KB2792100)Windows
Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2792100)Windows
Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2792100)Windows
Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2792100)Windows
Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB2792100)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2792100)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2792100)Windows
Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2792100)Windows
Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2792100)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2792100)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2792100)Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2792100)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2792100)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2792100)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2792100)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2792100) x86 based systemsWindows
Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2792100) x86 based systems for SP1Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2792100)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2792100)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2792100)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2792100)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2792100)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2792100) for SP1Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2792100)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2792100) for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2792100)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 (KB2792100)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2792100) x86 based systemsWindows
Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2792100) x86 based systems for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2792100)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2792100)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2792100)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2792100) for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2792100)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2792100)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 8 (KB2792100)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 8 x64 Edition (KB2792100)Windows
Cumulative Security Update for Internet Explorer 10 in Windows Server 2012 x64 Edition (KB2792100)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-13061Cumulative Security Update for Internet Explorer for Windows XP (KB2792100)
PATCH-13062Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2792100)
PATCH-13064Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2792100)
PATCH-13065Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2792100)
PATCH-13066Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB2792100)
PATCH-13067Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2792100)
PATCH-13068Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2792100)
PATCH-13069Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2792100)
PATCH-13070Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2792100)
PATCH-13071Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2792100)
PATCH-13072Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2792100)
PATCH-13073Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2792100)
PATCH-13074Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2792100)
PATCH-13075Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2792100)
PATCH-13076Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2792100)
PATCH-13077Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2792100)
PATCH-13078Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2792100)
PATCH-13079Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2792100)
PATCH-13080Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2792100)
PATCH-13081Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2792100)
PATCH-13082Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2792100)
PATCH-13083Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2792100)
PATCH-13084Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2792100)
PATCH-13085Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2792100)
PATCH-13086Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2792100)
PATCH-13087Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2792100)
PATCH-13088Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 (KB2792100)
PATCH-13089Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2792100)
PATCH-13090Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2792100)
PATCH-13091Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2792100)
PATCH-13092Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2792100)
PATCH-13093Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2792100)
PATCH-13094Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2792100)
PATCH-13095Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2792100)
PATCH-13097Cumulative Security Update for Internet Explorer 10 in Windows 8 (KB2792100)
PATCH-13098Cumulative Security Update for Internet Explorer 10 in Windows 8 x64 Edition (KB2792100)
PATCH-13099Cumulative Security Update for Internet Explorer 10 in Windows Server 2012 x64 Edition (KB2792100)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234