Vulnerability Name:
CVE-2013-0024 (CCN-81629)
Assigned:
2012-11-27
Published:
2013-02-12
Updated:
2020-09-28
Summary:
Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer pasteHTML Use After Free Vulnerability."
CVSS v3 Severity:
10.0 Critical
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Changed
Impact Metrics:
Confidentiality (C):
High
Integrity (I):
High
Availibility (A):
High
CVSS v2 Severity:
9.3 High
(CVSS v2 Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C
)
6.9 Medium
(Temporal CVSS v2 Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
9.3 High
(CCN CVSS v2 Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C
)
6.9 Medium
(CCN Temporal CVSS v2 Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
Vulnerability Type:
CWE-399
Vulnerability Consequences:
Gain Access
References:
Source: MITRE
Type: CNA
CVE-2013-0024
Source: CCN
Type: Microsoft Security Bulletin MS13-009
Cumulative Security Update for Internet Explorer (2792100)
Source: CCN
Type: Microsoft Security Bulletin MS13-021
Cumulative Security Update for Internet Explorer (2809289)
Source: CCN
Type: Microsoft Security Bulletin MS13-028
Cumulative Security Update for Internet Explorer (2817183)
Source: CCN
Type: Microsoft Security Bulletin MS13-037
Cumulative Security Update for Internet Explorer (2829530)
Source: CCN
Type: Microsoft Security Bulletin MS13-047
Cumulative Security Update for Internet Explorer (2838727)
Source: CCN
Type: Microsoft Security Bulletin MS13-055
Cumulative Security Update for Internet Explorer (2846071)
Source: CCN
Type: Microsoft Security Bulletin MS13-059
Cumulative Security Update for Internet Explorer (2862772)
Source: CCN
Type: Microsoft Security Bulletin MS13-069
Cumulative Security Update for Internet Explorer (2870699)
Source: CCN
Type: Microsoft Security Bulletin MS13-080
Cumulative Security Update for Internet Explorer (2879017)
Source: CCN
Type: BID-57829
Microsoft Internet Explorer pasteHTML Use-After-Free Remote Code Execution Vulnerability
Source: CERT
Type: Third Party Advisory, US Government Resource
TA13-043B
Source: MS
Type: UNKNOWN
MS13-009
Source: XF
Type: UNKNOWN
msie-pastehtml-code-exec(81629)
Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:16126
Source: CCN
Type: ZDI-13-027
Microsoft Internet Explorer pasteHTML Use-After-Free Remote Code Execution Vulnerability
Vulnerable Configuration:
Configuration 1
:
cpe:/a:microsoft:internet_explorer:9:*:*:*:*:*:*:*
AND
cpe:/o:microsoft:windows_7:*:*:x64:*:*:*:*:*
OR
cpe:/o:microsoft:windows_7:*:*:x86:*:*:*:*:*
OR
cpe:/o:microsoft:windows_7:*:sp1:x64:*:*:*:*:*
OR
cpe:/o:microsoft:windows_7:*:sp1:x86:*:*:*:*:*
OR
cpe:/o:microsoft:windows_server_2008:*:r2:x64:*:*:*:*:*
OR
cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x64:*
OR
cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:x32:*
OR
cpe:/o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_vista:*:sp2:x64:*:*:*:*:*
Configuration 2
:
cpe:/a:microsoft:internet_explorer:8:*:*:*:*:*:*:*
AND
cpe:/o:microsoft:windows_7:-:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_7:-:sp1:*:*:ultimate_n:*:x64:*
OR
cpe:/o:microsoft:windows_7:-:sp1:*:*:ultimate_n:*:x86:*
OR
cpe:/o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_server_2008:*:r2:itanium:*:*:*:*:*
OR
cpe:/o:microsoft:windows_server_2008:*:r2:x64:*:*:*:*:*
OR
cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x64:*
OR
cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:x32:*
OR
cpe:/o:microsoft:windows_vista:*:sp2:x64:*:*:*:*:*
OR
cpe:/o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_xp:-:sp2:x64:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:microsoft:internet_explorer:9:*:*:*:*:*:*:*
OR
cpe:/a:microsoft:internet_explorer:8:*:*:*:*:*:*:*
Denotes that component is vulnerable
Oval Definitions
Definition ID
Class
Title
Last Modified
oval:org.mitre.oval:def:16126
V
Internet Explorer pasteHTML use after free vulnerability - MS13-009
2014-08-18
BACK
microsoft
internet explorer 9
microsoft
windows 7 *
microsoft
windows 7 *
microsoft
windows 7 * sp1
microsoft
windows 7 * sp1
microsoft
windows server 2008 * r2
microsoft
windows server 2008 * sp2
microsoft
windows server 2008 * sp2
microsoft
windows vista * sp2
microsoft
windows vista * sp2
microsoft
internet explorer 8
microsoft
windows 7 -
microsoft
windows 7 - sp1
microsoft
windows 7 - sp1
microsoft
windows server 2003 * sp2
microsoft
windows server 2008 * r2
microsoft
windows server 2008 * r2
microsoft
windows server 2008 * sp2
microsoft
windows server 2008 * sp2
microsoft
windows vista * sp2
microsoft
windows vista - sp2
microsoft
windows xp * sp3
microsoft
windows xp - sp2
microsoft
ie 9
microsoft
ie 8