Back

HIGH KEV

Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll

Published Sep 18, 2013 ·Due Sep 2, 2025

Description

Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published Sep 18, 2013
Updated Oct 22, 2025
Reserved Jun 3, 2013
CISA Vulnrichment
Updated Aug 12, 2025
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner microsoft
Published Sep 18, 2013
Updated Oct 22, 2025
Exploited since Aug 12, 2025
EUVD-2013-3825