First published: Wed Oct 09 2013(Updated: )
Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability."
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | ||
Internet Explorer | =6 | |
Internet Explorer | =7 | |
Internet Explorer | =8 | |
Internet Explorer | =9 | |
Internet Explorer | =10 | |
Internet Explorer | =11-developer-preview | |
Internet Explorer | =11-release-preview | |
All of | ||
Internet Explorer | =6 | |
Any of | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
All of | ||
Internet Explorer | =7 | |
Any of | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
All of | ||
Internet Explorer | =8 | |
Any of | ||
Microsoft Windows 7 | =sp1 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Vista | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
All of | ||
Internet Explorer | =9 | |
Any of | ||
Microsoft Windows 7 | =sp1 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Vista | =sp2 | |
All of | ||
Internet Explorer | =10 | |
Any of | ||
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.0 | ||
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
All of | ||
Internet Explorer | =11 | |
Any of | ||
Microsoft Windows | ||
Microsoft Windows RT | ||
Microsoft Windows Server | =r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3897 has a critical severity rating as it allows remote attackers to execute arbitrary code.
To fix CVE-2013-3897, users should apply the latest Microsoft security updates for Internet Explorer.
CVE-2013-3897 affects Internet Explorer versions 6 through 11.
Yes, CVE-2013-3897 can cause a denial of service due to memory corruption.
CVE-2013-3897 is associated with attacks that use crafted JavaScript code, particularly exploiting the onpropertychange event.