RULE(RULE ID:322046)

Rule General Information
Release Date: 2019-06-27
Rule Name: Microsoft Internet Explorer DOMNodeRemoved Use After Free Condition Vulnerability (CVE-2013-3143)
Severity:
CVE ID:
Rule Protection Details
Description: Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3161.
Impact: A use-after-free vulnerability can be exploited by an attacker in the vulnerable product. Successful exploit may cause some adverse consequences, such as crash of the product, execution of arbitrary code.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: http://packetstormsecurity.com/files/140166/Microsoft-Internet-Explorer-9-IEFRAME-CMarkup..RemovePointerPos-Use-After-Free.html
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-055
ExploitDB:40923
http://blog.skylined.nl/20161214001.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://technet.microsoft.com/zh-cn/security/bulletin/ms13-055