Overview
Microsoft Internet Explorer 8 contains a use-after-free vulnerability in the CGenericElement object, which is currently being exploited in the wild.
Description
Microsoft Security Advisory 2847140 states: Internet Explorer 6, Internet Explorer 7, Internet Explorer 9, and Internet Explorer 10 are not affected by the vulnerability. |
Impact
A remote unauthenticated attacker may be able to run arbitrary code in the context of the user running Internet Explorer 8. |
Solution
Apply an Update |
Apply a Microsoft "Fix It" |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 9.4 | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Temporal | 8.9 | E:H/RL:W/RC:C |
Environmental | 6.7 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
- https://technet.microsoft.com/en-us/security/bulletin/ms13-038
- http://blogs.technet.com/b/srd/archive/2013/05/08/microsoft-quot-fix-it-quot-available-to-mitigate-internet-explorer-8-vulnerability.aspx
- http://technet.microsoft.com/en-us/security/advisory/2847140
- http://blogs.technet.com/b/msrc/archive/2013/05/03/microsoft-releases-security-advisory-2847140.aspx
- https://community.rapid7.com/community/metasploit/blog/2013/05/05/department-of-labor-ie-0day-now-available-at-metasploit
- http://dev.metasploit.com/redmine/projects/framework/repository/revisions/a33510e82135355548a529e5f0cb5ab7134d674d/entry/modules/exploits/windows/browser/ie_cgenericelement_uaf.rb
- http://labs.alienvault.com/labs/index.php/2013/u-s-department-of-labor-website-hacked-and-redirecting-to-malicious-code/
Acknowledgements
This vulnerability was discovered in the wild.
This document was written by Jared Allar.
Other Information
CVE IDs: | CVE-2013-1347 |
Date Public: | 2013-05-03 |
Date First Published: | 2013-05-06 |
Date Last Updated: | 2013-05-14 17:28 UTC |
Document Revision: | 29 |