CVE-2013-0025: Use After Free
Published Feb 13, 2013
·Updated
Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SLayoutRun Use After Free Vulnerability."
Affected Software
1 affected component
Microsoft Internet Explorer=8
Event History
Feb 13, 2013
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
Which systems are exposed to this issue?
The affected product identified in the available data is Microsoft Internet Explorer 8. Exploitation can be performed remotely through a crafted website.
2
What does an attacker need to exploit it?
An attacker needs to cause the target to access a crafted website that triggers access to a deleted object. No authentication is required according to the supplied vector.
3
What is the potential impact of successful exploitation?
Successful exploitation allows remote execution of arbitrary code. The supplied severity vector indicates confidentiality, integrity, and availability can all be fully affected.