|
|||
Rule General Information |
---|
Release Date: | 2019-06-27 | |
Rule Name: | Microsoft Internet Explorer DOMNodeRemoved Use After Free Condition Vulnerability (CVE-2013-3143) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3161. | |
Impact: | A use-after-free vulnerability can be exploited by an attacker in the vulnerable product. Successful exploit may cause some adverse consequences, such as crash of the product, execution of arbitrary code. | |
Affected OS: | Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others | |
Reference: | http://packetstormsecurity.com/files/140166/Microsoft-Internet-Explorer-9-IEFRAME-CMarkup..RemovePointerPos-Use-After-Free.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-055 ExploitDB:40923 http://blog.skylined.nl/20161214001.html |
|
Solutions |
---|
The vendors have released upgrade patches to fix vulnerabilities, please visit: http://technet.microsoft.com/zh-cn/security/bulletin/ms13-055 |