Microsoft Internet Explorer CVE-2013-3205 Memory Corruption Vulnerability
BID:62208
Info
Microsoft Internet Explorer CVE-2013-3205 Memory Corruption Vulnerability
| Bugtraq ID: | 62208 |
| Class: | Unknown |
| CVE: |
CVE-2013-3205 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2013 12:00AM |
| Updated: | Mar 19 2015 08:39AM |
| Credit: | Peter 'corelanc0d3r' Van Eeckhoutte of Corelan, working with HP's Zero Day Initiative |
| Vulnerable: |
Microsoft Internet Explorer 8 Microsoft Internet Explorer 7.0 Microsoft Internet Explorer 6.0 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5.2 Avaya Messaging Application Server 4 Avaya Meeting Exchange - Webportal 0 Avaya Conferencing Standard Edition 6.0 SP1 Avaya Conferencing Standard Edition 6.0 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 Avaya CallPilot 0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer CVE-2013-3205 Memory Corruption Vulnerability
Microsoft Internet Explorer is prone to a memory-corruption vulnerability due to a use-after-free error.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial-of-service conditions.
Microsoft Internet Explorer 6, 7, and 8 are affected.
Microsoft Internet Explorer is prone to a memory-corruption vulnerability due to a use-after-free error.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial-of-service conditions.
Microsoft Internet Explorer 6, 7, and 8 are affected.
Exploit / POC
Microsoft Internet Explorer CVE-2013-3205 Memory Corruption Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Solution / Fix
Microsoft Internet Explorer CVE-2013-3205 Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Microsoft Internet Explorer 7.0
Microsoft Internet Explorer 8
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Microsoft Internet Explorer 7.0
-
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB2870699)
http://www.microsoft.com/downloads/details.aspx?FamilyID=c082c458-529b -46e5-8037-283e07f1acb5 -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 64-bit Itanium Edition (K
http://www.microsoft.com/downloads/details.aspx?FamilyID=c00bef37-e7b8 -43e9-9e13-2306c3987d87 -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2870699)
http://www.microsoft.com/downloads/details.aspx?FamilyID=2f7ee3db-2864 -45be-8881-a13bca8e577f -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2870699)
http://www.microsoft.com/downloads/details.aspx?FamilyID=9e8895b3-b25e -4f51-99e1-35740c1dfd99 -
Microsoft Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2870699)
http://www.microsoft.com/downloads/details.aspx?FamilyID=36dcc1d4-01f0 -4bf6-9249-0b5d94bea0a4 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2870699)
http://www.microsoft.com/downloads/details.aspx?FamilyID=a3f002a7-ce28 -4488-b5ad-1f4687a88640 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 for Itanium-based Systems
http://www.microsoft.com/downloads/details.aspx?FamilyID=c5539f72-6ca5 -48f3-9ccf-2a0f69cb6139 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2870699)
http://www.microsoft.com/downloads/details.aspx?FamilyID=54acb316-c13e -4469-83c2-8be8bedbba6e -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2870699)
http://www.microsoft.com/downloads/details.aspx?FamilyID=84d24b9d-c889 -485a-9174-125c52db8e59 -
Microsoft Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2870699)
http://www.microsoft.com/downloads/details.aspx?FamilyID=18b2b2f8-3c09 -4737-9663-7845e518100f
Microsoft Internet Explorer 8
-
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2870699)
http://www.microsoft.com/downloads/details.aspx?familyid=d955138d-f3f0 -43eb-81ce-7c727282727b -
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2870699)
http://www.microsoft.com/downloads/details.aspx?familyid=be16be17-ecde -4c4c-97b6-1ced8fb7e3aa -
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2870699)
http://www.microsoft.com/downloads/details.aspx?familyid=530e879d-be55 -4c60-890e-e5bf918447e1 -
Microsoft Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2870699)
http://www.microsoft.com/downloads/details.aspx?familyid=0d4e46fb-7053 -41c4-8870-43d591448919 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2870699)
http://www.microsoft.com/downloads/details.aspx?familyid=ef4d181d-c955 -4b5f-b9d3-0944271809b2 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2870699)
http://www.microsoft.com/downloads/details.aspx?familyid=d7621078-15d6 -4bf9-a7ba-c3467f9b512a -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2870699)
http://www.microsoft.com/downloads/details.aspx?familyid=c17f1242-2a84 -4dee-b245-d9f0a2d0e65d -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 for Itanium-based Syste
http://www.microsoft.com/downloads/details.aspx?familyid=c4567388-9b76 -4203-833e-1bdf844cb51f -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2870699)
http://www.microsoft.com/downloads/details.aspx?familyid=eb8fd571-0f12 -48a9-ab4c-9b9abb06b043 -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2870699)
http://www.microsoft.com/downloads/details.aspx?familyid=8476f0e5-db41 -4e3a-a179-f15d527fe24b -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2870699)
http://www.microsoft.com/downloads/details.aspx?familyid=e3edd8d2-b767 -4a40-9ca2-e651abe5dc1e -
Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2870699)
http://www.microsoft.com/downloads/details.aspx?familyid=d286131a-4af5 -4133-b13b-ab8f7d4181c4
References
Microsoft Internet Explorer CVE-2013-3205 Memory Corruption Vulnerability
References:
References:
- Microsoft Internet Explorer Homepage (Microsoft)