CVE-2013-2551: Microsoft Internet Explorer Use-After-Free Vulnerability
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-1309.
Other sources
Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2551?
CVE-2013-2551 has a critical severity rating due to its use-after-free vulnerability that allows remote code execution.
How do I fix CVE-2013-2551?
To fix CVE-2013-2551, users should update Microsoft Internet Explorer to the latest version to mitigate the vulnerability.
Which versions of Internet Explorer are affected by CVE-2013-2551?
CVE-2013-2551 affects Internet Explorer versions 6, 7, 8, 9, and 10.
What are the potential impacts of CVE-2013-2551?
Exploitation of CVE-2013-2551 can lead to remote code execution, allowing attackers to gain control over affected systems.
Is CVE-2013-2551 still a threat today?
While CVE-2013-2551 is no longer actively exploited in the wild, unpatched systems may remain vulnerable if not updated.