CVE-2013-7331

Description

The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a res:// URL, and exploited in the wild in February 2014.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
EPSS Score
Exploitation Probability
81.812

Associated Vulnerability

VulnerabilityOS Platform
Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2977629)Windows
Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB2977629)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2977629)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2977629)Windows
Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2977629)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2977629)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2977629)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2977629)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2977629)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 (KB2977629)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2977629)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 7 (KB2977629)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 8 (KB2977629)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 7 x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 10 in Windows Server 2008 R2 x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 8 x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 10 in Windows Server 2012 x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 11 in Windows 7 (KB2977629)Windows
Cumulative Security Update for Internet Explorer 11 in Windows 7 x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 11 in Windows Server 2008 R2 x64 Edition (KB2977629)Windows
Cumulative Security Update for Internet Explorer 11 for Windows 8.1 for x64-based systems (KB2977629)Windows
Cumulative Security Update for Internet Explorer 11 for Windows Server 2012 R2 (KB2977629)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-16074Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2977629)
PATCH-16075Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2977629)
PATCH-16076Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB2977629)
PATCH-16077Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2977629)
PATCH-16078Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2977629)
PATCH-16079Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2977629)
PATCH-16080Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2977629)
PATCH-16081Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2977629)
PATCH-16082Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2977629)
PATCH-16083Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2977629)
PATCH-16084Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2977629)
PATCH-16085Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2977629)
PATCH-16086Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2977629)
PATCH-16087Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2977629)
PATCH-16088Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2977629)
PATCH-16089Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2977629)
PATCH-16090Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2977629)
PATCH-16091Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2977629)
PATCH-16093Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2977629)
PATCH-16094Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2977629)
PATCH-16095Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2977629)
PATCH-16096Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2977629)
PATCH-16097Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2977629)
PATCH-16098Cumulative Security Update for Internet Explorer 10 in Windows 7 (KB2977629)
PATCH-16099Cumulative Security Update for Internet Explorer 10 in Windows 8 (KB2977629)
PATCH-16100Cumulative Security Update for Internet Explorer 10 in Windows 7 x64 Edition (KB2977629)
PATCH-16101Cumulative Security Update for Internet Explorer 10 in Windows Server 2008 R2 x64 Edition (KB2977629)
PATCH-16102Cumulative Security Update for Internet Explorer 10 in Windows 8 x64 Edition (KB2977629)
PATCH-16103Cumulative Security Update for Internet Explorer 10 in Windows Server 2012 x64 Edition (KB2977629)
PATCH-16106Cumulative Security Update for Internet Explorer 11 in Windows 7 x64 Edition (KB2977629)
PATCH-16107Cumulative Security Update for Internet Explorer 11 in Windows Server 2008 R2 x64 Edition (KB2977629)
PATCH-16108Cumulative Security Update for Internet Explorer 11 for Windows 8.1 for x64-based systems (KB2977629)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234