First published: Wed Feb 26 2014(Updated: )
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a res:// URL, and exploited in the wild in February 2014.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | ||
All of | ||
Internet Explorer | =6 | |
Microsoft Windows Server | =sp2 | |
All of | ||
Internet Explorer | =7 | |
Any of | ||
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Vista | =sp2 | |
All of | ||
Internet Explorer | =8 | |
Any of | ||
Microsoft Windows 7 | =sp1 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Vista | =sp2 | |
All of | ||
Internet Explorer | =9 | |
Any of | ||
Microsoft Windows 7 | =sp1 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Vista | =sp2 | |
All of | ||
Internet Explorer | =10 | |
Any of | ||
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.0 | ||
Microsoft Windows RT | ||
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | ||
Microsoft Windows Vista | =sp2 | |
All of | ||
Internet Explorer | =11 | |
Any of | ||
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.1 | ||
Microsoft Windows RT | ||
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | =r2 | |
Internet Explorer | =6 | |
Microsoft Windows Server | =sp2 | |
Internet Explorer | =7 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Vista | =sp2 | |
Internet Explorer | =8 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows Server | =r2-sp1 | |
Microsoft Windows Server | =r2-sp1 | |
Internet Explorer | =9 | |
Internet Explorer | =10 | |
Microsoft Windows 8.0 | ||
Microsoft Windows RT | ||
Microsoft Windows Server | ||
Internet Explorer | =11 | |
Microsoft Windows 8.1 | ||
Microsoft Windows RT | ||
Microsoft Windows Server | =r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7331 is classified as a moderate severity vulnerability due to its potential for information disclosure.
To mitigate CVE-2013-7331, users should update to the latest version of Internet Explorer or apply relevant Microsoft patches.
CVE-2013-7331 affects Internet Explorer versions 6 through 11 on various versions of Windows.
CVE-2013-7331 is an information disclosure vulnerability that can expose local pathnames and intranet addresses.
Yes, CVE-2013-7331 can be exploited by remote attackers to gather sensitive information from the affected systems.