Microsoft Internet Explorer CVE-2013-1347 Use-After-Free Remote Code Execution Vulnerability
BID:59641
Info
Microsoft Internet Explorer CVE-2013-1347 Use-After-Free Remote Code Execution Vulnerability
| Bugtraq ID: | 59641 |
| Class: | Design Error |
| CVE: |
CVE-2013-1347 |
| Remote: | Yes |
| Local: | No |
| Published: | May 03 2013 12:00AM |
| Updated: | Mar 19 2015 09:30AM |
| Credit: | Daniel Caselden of FireEye and iSIGHT Partners |
| Vulnerable: |
Microsoft Internet Explorer 8 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5.2 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Meeting Exchange - Webportal 0 Avaya Conferencing Standard Edition 6.0 SP1 Avaya Conferencing Standard Edition 6.0 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer CVE-2013-1347 Use-After-Free Remote Code Execution Vulnerability
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial-of-service conditions.
Microsoft Internet Explorer version 8 is affected.
Microsoft Internet Explorer is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user to view a specially crafted webpage.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial-of-service conditions.
Microsoft Internet Explorer version 8 is affected.
Exploit / POC
Microsoft Internet Explorer CVE-2013-1347 Use-After-Free Remote Code Execution Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This issue is being exploited in the wild through exploit toolkits.
The following metasploit exploit module is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This issue is being exploited in the wild through exploit toolkits.
The following metasploit exploit module is available:
Solution / Fix
Microsoft Internet Explorer CVE-2013-1347 Use-After-Free Remote Code Execution Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
The payloads delivered by the exploit kits are detected by Symantec as 'Trojan.Zbot' and 'Trojan.Horse'.
Microsoft Internet Explorer 8
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
The payloads delivered by the exploit kits are detected by Symantec as 'Trojan.Zbot' and 'Trojan.Horse'.
Microsoft Internet Explorer 8
-
Microsoft Security Update for Internet Explorer 8 for Windows Server 2003 (KB2847204)
http://www.microsoft.com/downloads/details.aspx?familyid=4358f330-2218 -4a86-a66f-9d81270d7dd2 -
Microsoft Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2847204)
http://www.microsoft.com/downloads/details.aspx?familyid=e8fe8689-716a -43ea-9a6b-bc165fdf8bb4 -
Microsoft Security Update for Internet Explorer 8 for Windows XP (KB2847204)
http://www.microsoft.com/downloads/details.aspx?familyid=559f95b2-d03e -40f6-885c-d2d4803bda35 -
Microsoft Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2847204)
http://www.microsoft.com/downloads/details.aspx?familyid=50924de9-5fe3 -424f-a649-950d06df1e62 -
Microsoft Security Update for Internet Explorer 8 in Windows 7 (KB2847204)
http://www.microsoft.com/downloads/details.aspx?familyid=49cad8af-a589 -4115-887a-63f883d365c2 -
Microsoft Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2847204)
http://www.microsoft.com/downloads/details.aspx?familyid=e807d4ca-5856 -4c85-b637-209d1e4e97f1 -
Microsoft Security Update for Internet Explorer 8 in Windows Server 2008 (KB2847204)
http://www.microsoft.com/downloads/details.aspx?familyid=de6d60e6-0168 -4c91-b4f5-b67097f72603 -
Microsoft Security Update for Internet Explorer 8 in Windows Server 2008 R2 for Itanium-based Systems (KB28472
http://www.microsoft.com/downloads/details.aspx?familyid=127fb1a3-b199 -4801-80c9-24cf7d71d7d7 -
Microsoft Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2847204)
http://www.microsoft.com/downloads/details.aspx?familyid=1f1f2484-364b -4aa1-8c4e-275a420818b8 -
Microsoft Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2847204)
http://www.microsoft.com/downloads/details.aspx?familyid=76d5934a-d9b3 -4412-8dce-ee9f91e83426 -
Microsoft Security Update for Internet Explorer 8 in Windows Vista (KB2847204)
http://www.microsoft.com/downloads/details.aspx?familyid=a49bf78f-3f50 -4839-8d5c-718dc701bf67 -
Microsoft Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2847204)
http://www.microsoft.com/downloads/details.aspx?familyid=1f6fce66-cd2a -4cf6-9521-5cefce20456a
References
Microsoft Internet Explorer CVE-2013-1347 Use-After-Free Remote Code Execution Vulnerability
References:
References:
- "Private Exploit Pack" - new BEP featuring CVE-2013-1347 (Malware don't need Coffee)
- Microsoft Internet Explorer Homepage (Microsoft)
- Microsoft Security Advisory (2847140) Vulnerability in Internet Explorer (Microsoft)
- Microsoft Internet Explorer 8 CGenericElement object use-after-free vulnerabilit (US-CERT)
- Microsoft Security Bulletin MS13-038 (Microsoft)
- MS13-038 Security Update for Internet Explorer (2847204) (Avaya)