RULE(RULE ID:310416)

Rule General Information
Release Date: 2018-09-18
Rule Name: WEB-CLIENT Microsoft Internet Explorer Onlosecaputre Event Use-after-free Vulnerability(CVE-2013-3893)
Severity:
CVE ID:
Rule Protection Details
Description: Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings.
Impact: A use-after-free vulnerability can be exploited by an attacker in the vulnerable product. Successful exploit may cause some adverse consequences, such as crash of the product, execution of arbitrary code.
Affected OS: Windows
Reference: http://technet.microsoft.com/security/advisory/2887505
MicrosoftSecurityBulletin:MS13-080
SecurityFocusBID:62453
Solutions
Microsoft has released a patch MS13-080 to eliminate the vulnerability. The patch can be downloaded at http://blogs.technet.com/b/srd/archive/2013/10/08/ms13-080-addresses-two-vulnerabilities-under-limited-targeted-attacks.aspx