CVE-2013-1347

Description

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
86.916

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Internet Explorer 8 for Windows XP (KB2847204)Windows
Security Update for Internet Explorer 8 for Windows Server 2003 (KB2847204)Windows
Security Update for Internet Explorer 8 in Windows Vista (KB2847204)Windows
Security Update for Internet Explorer 8 in Windows Server 2008 (KB2847204)Windows
Security Update for Internet Explorer 8 in Windows 7 (KB2847204)Windows
Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2847204)Windows
Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2847204)Windows
Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2847204)Windows
Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2847204)Windows
Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2847204)Windows
Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2847204)Windows
Security Update for Internet Explorer 9 in Windows Vista (KB2847204)Windows
Security Update for Internet Explorer 9 in Windows Server 2008 (KB2847204)Windows
Security Update for Internet Explorer 9 in Windows 7 (KB2847204)Windows
Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2847204)Windows
Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2847204)Windows
Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2847204)Windows
Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2847204)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-13611Security Update for Internet Explorer 8 for Windows XP (KB2847204)
PATCH-13612Security Update for Internet Explorer 8 for Windows Server 2003 (KB2847204)
PATCH-13613Security Update for Internet Explorer 8 in Windows Vista (KB2847204)
PATCH-13614Security Update for Internet Explorer 8 in Windows Server 2008 (KB2847204)
PATCH-13615Security Update for Internet Explorer 8 in Windows 7 (KB2847204)
PATCH-13616Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2847204)
PATCH-13617Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2847204)
PATCH-13618Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2847204)
PATCH-13619Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2847204)
PATCH-13620Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2847204)
PATCH-13621Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2847204)
PATCH-13622Security Update for Internet Explorer 9 in Windows Vista (KB2847204)
PATCH-13623Security Update for Internet Explorer 9 in Windows Server 2008 (KB2847204)
PATCH-13624Security Update for Internet Explorer 9 in Windows 7 (KB2847204)
PATCH-13625Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2847204)
PATCH-13626Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2847204)
PATCH-13627Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2847204)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234