CVE-2013-0018: Use After Free
Published Feb 13, 2013
·Updated
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SetCapture Use After Free Vulnerability."
Affected Software
4 affected components
Microsoft Internet Explorer=6
Microsoft Internet Explorer=7
Microsoft Internet Explorer=8
Microsoft Internet Explorer=9
Event History
Feb 13, 2013
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
Which systems are exposed to this issue?
Systems running Microsoft Internet Explorer versions 6 through 9 are affected. The vulnerability can be reached remotely through a crafted website.
2
What does an attacker need to exploit it?
An attacker does not need authentication. They need to cause the victim to access a crafted website that triggers access to a deleted object.
3
What is the likely impact of successful exploitation?
Successful exploitation allows remote execution of arbitrary code and can affect confidentiality, integrity, and availability.