CVE-2013-5056

Description

Use-after-free vulnerability in the Scripting Runtime Object Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site that is visited with Internet Explorer, aka Use-After-Free Vulnerability in Microsoft Scripting Runtime Object Library.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
33.612

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows XP (KB2892075)Windows
Security Update for Windows Server 2003 (KB2892075)Windows
Security Update for Windows Vista (KB2892075)Windows
Security Update for Windows Server 2008 (KB2892075)Windows
Security Update for Windows Server 2012 R2 (KB2892074)Windows
Security Update for Windows 7 (KB2892074)Windows
Security Update for Windows XP x64 Edition (KB2892075)Windows
Security Update for Windows Server 2003 x64 Edition (KB2892075)Windows
Security Update for Windows Vista for x64-based Systems (KB2892075)Windows
Security Update for Windows Server 2008 x64 Edition (KB2892075)Windows
Security Update for Windows 8.1 for x64-based Systems (KB2892074)Windows
Security Update for Windows 7 for x64-based Systems (KB2892074)Windows
Security Update for Windows 8.1 (KB2892074)Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB2892074)Windows
Security Update for Windows 8 (KB2892074)Windows
Security Update for Windows 8 for x64-based Systems (KB2892074)Windows
Security Update for Windows Server 2012 (KB2892074)Windows
Security Update for Windows Server 2003 (KB2892076)Windows
Security Update for Windows XP x64 Edition (KB2892076)Windows
Security Update for Windows Server 2003 x64 Edition (KB2892076)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-14882Security Update for Windows Server 2003 (KB2892075)
PATCH-14883Security Update for Windows Vista (KB2892075)
PATCH-14884Security Update for Windows Server 2008 (KB2892075)
PATCH-14885Security Update for Windows Server 2012 R2 (KB2892074)
PATCH-14886Security Update for Windows 7 (KB2892074)
PATCH-14887Security Update for Windows XP x64 Edition (KB2892075)
PATCH-14888Security Update for Windows Server 2003 x64 Edition (KB2892075)
PATCH-14889Security Update for Windows Vista for x64-based Systems (KB2892075)
PATCH-14890Security Update for Windows Server 2008 x64 Edition (KB2892075)
PATCH-14891Security Update for Windows 8.1 for x64-based Systems (KB2892074)
PATCH-14892Security Update for Windows 7 for x64-based Systems (KB2892074)
PATCH-14893Security Update for Windows 8.1 (KB2892074)
PATCH-14894Security Update for Windows Server 2008 R2 x64 Edition (KB2892074)
PATCH-14895Security Update for Windows 8 (KB2892074)
PATCH-14896Security Update for Windows 8 for x64-based Systems (KB2892074)
PATCH-14897Security Update for Windows Server 2012 (KB2892074)
PATCH-14898Security Update for Windows Server 2003 (KB2892076)
PATCH-14899Security Update for Windows XP x64 Edition (KB2892076)
PATCH-14900Security Update for Windows Server 2003 x64 Edition (KB2892076)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234