CVE-2013-2551

Description

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka Internet Explorer Use After Free Vulnerability, a different vulnerability than CVE-2013-1308 and CVE-2013-1309.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
91.271

Associated Vulnerability

VulnerabilityOS Platform
Cumulative Security Update for Internet Explorer for Windows XP (KB2829530)Windows
Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2829530)Windows
Cumulative Security Update for Internet Explorer for Windows XP x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2829530)Windows
Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB2829530)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2829530)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2829530)Windows
Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2829530)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2829530)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2829530)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2829530)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2829530)Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2829530)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 (KB2829530)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2829530)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 7 (KB2829530)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 8 (KB2829530)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 7 x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 10 in Windows Server 2008 R2 x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 8 x64 Edition (KB2829530)Windows
Cumulative Security Update for Internet Explorer 10 in Windows Server 2012 x64 Edition (KB2829530)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-13568Cumulative Security Update for Internet Explorer for Windows XP (KB2829530)
PATCH-13569Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2829530)
PATCH-13570Cumulative Security Update for Internet Explorer for Windows XP x64 Edition (KB2829530)
PATCH-13571Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2829530)
PATCH-13572Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2829530)
PATCH-13573Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB2829530)
PATCH-13574Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2829530)
PATCH-13575Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2829530)
PATCH-13576Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2829530)
PATCH-13577Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2829530)
PATCH-13578Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2829530)
PATCH-13579Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2829530)
PATCH-13580Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2829530)
PATCH-13581Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2829530)
PATCH-13582Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2829530)
PATCH-13583Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2829530)
PATCH-13584Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2829530)
PATCH-13585Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2829530)
PATCH-13586Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2829530)
PATCH-13587Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2829530)
PATCH-13588Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2829530)
PATCH-13589Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2829530)
PATCH-13590Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2829530)
PATCH-13591Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2829530)
PATCH-13593Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2829530)
PATCH-13594Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2829530)
PATCH-13595Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2829530)
PATCH-13596Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2829530)
PATCH-13598Cumulative Security Update for Internet Explorer 10 in Windows 7 (KB2829530)
PATCH-13599Cumulative Security Update for Internet Explorer 10 in Windows 8 (KB2829530)
PATCH-13601Cumulative Security Update for Internet Explorer 10 in Windows Server 2008 R2 x64 Edition (KB2829530)
PATCH-13602Cumulative Security Update for Internet Explorer 10 in Windows 8 x64 Edition (KB2829530)
PATCH-13603Cumulative Security Update for Internet Explorer 10 in Windows Server 2012 x64 Edition (KB2829530)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234