Microsoft Internet Explorer CVE-2013-3846 Memory Corruption Vulnerability
BID:62372
Info
Microsoft Internet Explorer CVE-2013-3846 Memory Corruption Vulnerability
| Bugtraq ID: | 62372 |
| Class: | Unknown |
| CVE: |
CVE-2013-3846 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2013 12:00AM |
| Updated: | Sep 05 2013 12:00AM |
| Credit: | Amol Naik, working with HP's Zero Day Initiative. |
| Vulnerable: |
Microsoft Internet Explorer 9 Microsoft Internet Explorer 10 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer CVE-2013-3846 Memory Corruption Vulnerability
Microsoft Internet Explorer is prone to a memory-corruption vulnerability due to a use-after-free condition.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial-of-service conditions.
Internet Explorer versions 9 and 10 are affected.
Microsoft Internet Explorer is prone to a memory-corruption vulnerability due to a use-after-free condition.
Attackers can exploit this issue to execute arbitrary code in the context of the currently logged-in user. Failed attacks will cause denial-of-service conditions.
Internet Explorer versions 9 and 10 are affected.
Exploit / POC
Microsoft Internet Explorer CVE-2013-3846 Memory Corruption Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Internet Explorer CVE-2013-3846 Memory Corruption Vulnerability
References:
References:
- Microsoft Internet Explorer Homepage (Microsoft)
- Microsoft Security Bulletin MS13-055 (Microsoft)
- ZDI-13-231: Microsoft Internet Explorer CTreePos Use-After-Free Remote Code Exec (TippingPoint Zero Day Initiative)