CVE-2013-3897

Description

Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka Internet Explorer Memory Corruption Vulnerability.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
90.548

Associated Vulnerability

VulnerabilityOS Platform
Cumulative Security Update for Internet Explorer for Windows XP (KB2879017)Windows
Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2879017)Windows
Cumulative Security Update for Internet Explorer for Windows XP x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2879017)Windows
Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB2879017)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2879017)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2879017)Windows
Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2879017)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2879017)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2879017)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2879017)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2879017)Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2879017)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 (KB2879017)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2879017)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 7 (KB2879017)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 8 (KB2879017)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 7 x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 10 in Windows Server 2008 R2 x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 8 x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 10 in Windows Server 2012 x64 Edition (KB2879017)Windows
Cumulative Security Update for Internet Explorer 11 for Windows 8.1 (KB2884101)Windows
Cumulative Security Update for Internet Explorer 11 for Windows 8.1 for x64-based systems (KB2884101)Windows
Cumulative Security Update for Internet Explorer 11 for Windows Server 2012 R2 (KB2884101)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-14428Cumulative Security Update for Internet Explorer for Windows XP (KB2879017)
PATCH-14429Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2879017)
PATCH-14430Cumulative Security Update for Internet Explorer for Windows XP x64 Edition (KB2879017)
PATCH-14431Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2879017)
PATCH-14432Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2879017)
PATCH-14433Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB2879017)
PATCH-14434Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2879017)
PATCH-14435Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2879017)
PATCH-14436Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2879017)
PATCH-14437Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2879017)
PATCH-14438Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2879017)
PATCH-14439Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2879017)
PATCH-14440Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2879017)
PATCH-14441Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2879017)
PATCH-14442Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2879017)
PATCH-14443Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2879017)
PATCH-14444Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2879017)
PATCH-14445Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2879017)
PATCH-14446Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2879017)
PATCH-14447Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2879017)
PATCH-14448Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2879017)
PATCH-14449Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2879017)
PATCH-14450Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2879017)
PATCH-14451Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2879017)
PATCH-14453Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2879017)
PATCH-14454Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2879017)
PATCH-14455Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2879017)
PATCH-14456Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2879017)
PATCH-14458Cumulative Security Update for Internet Explorer 10 in Windows 7 (KB2879017)
PATCH-14459Cumulative Security Update for Internet Explorer 10 in Windows 8 (KB2879017)
PATCH-14461Cumulative Security Update for Internet Explorer 10 in Windows Server 2008 R2 x64 Edition (KB2879017)
PATCH-14462Cumulative Security Update for Internet Explorer 10 in Windows 8 x64 Edition (KB2879017)
PATCH-14463Cumulative Security Update for Internet Explorer 10 in Windows Server 2012 x64 Edition (KB2879017)
PATCH-14631Cumulative Security Update for Internet Explorer 11 for Windows 8.1 (KB2884101)
PATCH-14664Cumulative Security Update for Internet Explorer 11 for Windows 8.1 for x64-based systems (KB2884101)
PATCH-14665Cumulative Security Update for Internet Explorer 11 for Windows Server 2012 R2 (KB2884101)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234