HIGH KEV
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll
Published Sep 18, 2013 ·Due Sep 2, 2025
8.8
HIGHCVSS 3.1
EPSS 87.53%
Description
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll.
Affected products
No data.
OR
- 6
- 7
- 8
- 9
- 10
- 11
- 11
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (13)
- http://blogs.technet.com/b/srd/archive/2013/09/17/cve-2013-3893-fix-it-workaround-available.aspx x_refsource_CONFIRMExploit
- http://blogs.technet.com/b/srd/archive/2013/10/08/ms13-080-addresses-two-vulnerabilities-under-limited-targeted-attacks.aspx x_refsource_CONFIRMVendor Advisory
- http://jvn.jp/en/jp/JVN27443259/index.html third-party-advisoryx_refsource_JVNThird Party Advisory
- http://jvndb.jvn.jp/ja/contents/2013/JVNDB-2013-000093.html third-party-advisoryx_refsource_JVNDBThird Party Advisory
- http://packetstormsecurity.com/files/162585/Microsoft-Internet-Explorer-8-SetMouseCapture-Use-After-Free.html x_refsource_MISCExploit
- http://pastebin.com/raw.php?i=Hx1L5gu6 x_refsource_MISCExploit
- http://technet.microsoft.com/security/advisory/2887505 x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/62453 vdb-entryx_refsource_BIDBroken Link
- http://www.us-cert.gov/ncas/alerts/TA13-288A third-party-advisoryx_refsource_CERTUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-080 vendor-advisoryx_refsource_MSVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-3825 Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18665 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-3893 government-resourceUS Government Resource
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published Sep 18, 2013
Updated Oct 22, 2025
Reserved Jun 3, 2013
Link CVE-2013-3893
CISA Vulnrichment
Updated Aug 12, 2025
ENISA EUVD
EUVD-2013-3825 Assigner microsoft
Published Sep 18, 2013
Updated Oct 22, 2025
Exploited since Aug 12, 2025
Link EUVD-2013-3825