CVE-2013-0028: Use After Free
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CObjectElement Use After Free Vulnerability."
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Systems running Microsoft Internet Explorer versions 6 through 9 are affected. Exploitation can be performed remotely through a crafted website.
What does an attacker need to exploit it?
The attacker needs to cause a user to access a crafted website that triggers access to a deleted object in Internet Explorer. No authentication is required according to the provided vector.
What is the potential impact of successful exploitation?
A successful exploit allows remote execution of arbitrary code. The vulnerability has critical severity with confidentiality, integrity, and availability impacts all rated complete.