Oval Definition:oval:org.mitre.oval:def:16727
Revision Date:2014-08-18Version:46
Title:Internet Explorer Use After Free Vulnerability - MS13-038
Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2013-1347
Platform(s):Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Microsoft Internet Explorer 8
Microsoft Internet Explorer 9
Definition Synopsis
  • IE 8 vulnerable versions
  • Microsoft Internet Explorer 8 is installed
  • AND vulnerable OS and file version
  • Win XP / 2K3 and vulnerable file versions
  • Win XP / 2K3
  • Microsoft Windows XP (32-bit) is installed
  • OR Microsoft Windows XP x64 is installed
  • OR Microsoft Windows Server 2003 (32-bit) is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • AND Check if the version of mshtml.dll is less than 8.0.6001.23487
  • OR Vista / 2K8 and vulnerable file version
  • Vista / 2K8
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • AND LDR/GDR
  • Check if the version of mshtml.dll is less than 8.0.6001.19421
  • OR Win7/R2 and vulnerable file version
  • Win 7 / R2
  • Microsoft Windows 7 (32-bit) is installed
  • OR Microsoft Windows 7 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 Itanium-Based Edition is installed
  • AND Check for vulnerable versions
  • Check if the version of mshtml.dll is less than 8.0.7601.18129
  • OR IE 9 vulnerable versions
  • Microsoft Internet Explorer 9 is installed
  • AND Vista / 2K8 / Win 7 / R2
  • Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows 7 (32-bit) is installed
  • OR Microsoft Windows 7 x64 Edition is installed
  • OR Microsoft Windows Server 2008 R2 x64 Edition is installed
  • AND Check for vulnerable versions
  • Check if the version of mshtml.dll is less than 9.0.8112.16484
  • OR Check for LDR
  • Mshtml.dll version is greater than or equal to 9.0.8112.20000
  • AND Check if the version of mshtml.dll is less than 9.0.8112.20594
  • BACK