CVE-2013-3163: Microsoft Internet Explorer Memory Corruption Vulnerability
Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and CVE-2013-3151.
Other sources
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Disconnect Internet Explorer (versions 8 through 10) from networks if still in use: isolate systems running these IE versions, and implement network-level controls such as firewall/ACL rules to block outbound and inbound HTTP/HTTPS access for those hosts until they are no longer in use.
Event History
Frequently Asked Questions
What is CVE-2013-3163?
CVE-2013-3163 refers to a memory corruption vulnerability in Microsoft Internet Explorer that allows remote attackers to execute code or cause a denial of service through a crafted website.
How does CVE-2013-3163 affect Microsoft Internet Explorer?
CVE-2013-3163 affects Microsoft Internet Explorer by creating a memory corruption vulnerability that can be exploited by remote attackers.
What is the severity level of CVE-2013-3163?
The severity level of CVE-2013-3163 is not specified in the provided information.
Is there a fix available for CVE-2013-3163?
Yes, Microsoft released a security update (MS13-055) to address CVE-2013-3163. It is recommended to install this update to mitigate the vulnerability.
Where can I find more information about CVE-2013-3163?
You can find more information about CVE-2013-3163 on the Microsoft website: https://learn.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-055