CVE-2013-0094: Use After Free
Published Mar 13, 2013
·Updated
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer removeChild Use After Free Vulnerability."
Affected Software
62 affected components
All of the following
Microsoft Internet Explorer=6
Any of the following
Microsoft Windows Server 2003=sp2
Microsoft Windows XP=sp2
Microsoft Windows XP=sp3
All of the following
Microsoft Internet Explorer=7
Any of the following
Microsoft Windows Server 2003=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
Microsoft Windows Vista=sp2
Microsoft Windows XP=sp2
Microsoft Windows XP=sp3
All of the following
Microsoft Internet Explorer=8
Any of the following
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows 7=sp1
Microsoft Windows Server 2003=sp2
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
Microsoft Windows Vista=sp2
Microsoft Windows XP=sp2
Microsoft Windows XP=sp3
All of the following
Microsoft Internet Explorer=9
Any of the following
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows 7=sp1
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
Microsoft Windows Vista=sp2
All of the following
Microsoft Internet Explorer=10
Any of the following
Microsoft Windows 8
Microsoft Windows 8
Microsoft Windows RT
Microsoft Windows Server 2012
Microsoft Internet Explorer=6
Microsoft Windows Server 2003=sp2
Microsoft Windows XP=sp2
Microsoft Windows XP=sp3
Microsoft Internet Explorer=7
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
Microsoft Windows Vista=sp2
Microsoft Internet Explorer=8
Microsoft Windows 7
Microsoft Windows 7=sp1
Microsoft Windows 7=sp1
Microsoft Windows Server 2008=r2
Microsoft Windows Server 2008=r2
Microsoft Internet Explorer=9
Microsoft Internet Explorer=10
Microsoft Windows 8
Microsoft Windows 8
Microsoft Windows RT
Microsoft Windows Server 2012
Event History
Mar 13, 2013
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-0094?
CVE-2013-0094 has a severity rating of Critical, allowing remote attackers to execute arbitrary code.
2
How do I fix CVE-2013-0094?
To fix CVE-2013-0094, update Microsoft Internet Explorer to the latest version provided by Microsoft.
3
Which versions of Internet Explorer are affected by CVE-2013-0094?
CVE-2013-0094 affects Microsoft Internet Explorer versions 6, 7, 8, 9, and 10.
4
What systems are vulnerable to CVE-2013-0094?
CVE-2013-0094 primarily affects systems running Windows XP, Windows Vista, Windows 7, Windows Server 2003, and Windows Server 2008.
5
Is CVE-2013-0094 actively exploited in the wild?
Yes, CVE-2013-0094 has been reported as actively exploited in targeted attacks.