CVE-2013-0024: Use After Free
Published Feb 13, 2013
·Updated
Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer pasteHTML Use After Free Vulnerability."
Affected Software
45 affected components
All of the following
Microsoft Internet Explorer=9
Any of the following
Microsoft Windows 7
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows 7=sp1
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
All of the following
Microsoft Internet Explorer=8
Any of the following
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows 7=sp1
Microsoft Windows Server 2003=sp2
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
Microsoft Windows Vista=sp2
Microsoft Windows XP=sp3
Microsoft Windows XP=sp2
Microsoft Internet Explorer=9
Microsoft Windows 7
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows 7=sp1
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
Microsoft Windows Vista=sp2
Microsoft Internet Explorer=8
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows 7=sp1
Microsoft Windows Server 2003=sp2
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
Microsoft Windows Vista=sp2
Microsoft Windows XP=sp3
Microsoft Windows XP=sp2
Event History
Feb 13, 2013
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-0024?
CVE-2013-0024 is rated as critical due to the potential for arbitrary code execution by attackers.
2
How do I fix CVE-2013-0024?
To remediate CVE-2013-0024, apply the security updates provided by Microsoft for Internet Explorer 8 and 9.
3
Which versions of Internet Explorer are affected by CVE-2013-0024?
CVE-2013-0024 affects Internet Explorer versions 8 and 9.
4
Can CVE-2013-0024 be exploited by visiting websites?
Yes, CVE-2013-0024 can be exploited by visiting a malicious website that triggers the vulnerability.
5
What are the potential impacts of CVE-2013-0024?
Exploitation of CVE-2013-0024 can lead to unauthorized access and execution of malicious code on the victim's system.