CVE-2013-3897: Microsoft Internet Explorer Use-After-Free Vulnerability
Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability."
Other sources
A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3897?
CVE-2013-3897 has a critical severity rating as it allows remote attackers to execute arbitrary code.
How do I fix CVE-2013-3897?
To fix CVE-2013-3897, users should apply the latest Microsoft security updates for Internet Explorer.
Which versions of Internet Explorer are affected by CVE-2013-3897?
CVE-2013-3897 affects Internet Explorer versions 6 through 11.
Can CVE-2013-3897 lead to denial of service?
Yes, CVE-2013-3897 can cause a denial of service due to memory corruption.
What kind of attack is associated with CVE-2013-3897?
CVE-2013-3897 is associated with attacks that use crafted JavaScript code, particularly exploiting the onpropertychange event.