RULE(RULE ID:310349)

Rule General Information
Release Date: 2019-04-30
Rule Name: Microsoft Internet Explorer applyElement Use After Free Vulnerability (CVE-2013-3112)
Severity:
CVE ID:
CNNVD ID:
Rule Protection Details
Description: Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability,".
Impact: A use-after-free vulnerability can be exploited by an attacker in the vulnerable product. Successful exploit may cause some adverse consequences, such as crash of the product, execution of arbitrary code.
Affected OS: Windows
Reference: https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-047
http://www.us-cert.gov/ncas/alerts/TA13-168A
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16477
Solutions
Microsoft has released a patch MS13-047 to eliminate the vulnerability. The patch can be downloaded at:
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-047