Skip to content
COOEY

EXPOSURES › CVE-2013-3897

CVE-2013-3897

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2013-3897 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

A use-after-free vulnerability in Internet Explorer allowed remote code execution, and the browser was already end-of-life and unsupported.

Internet Explorer's use-after-free flaw in CDisplayPointer enabled remote code execution, a risk compounded by the browser's end-of-life status and lack of patches. DIB organizations must avoid unsupported software like IE, as its history of critical vulnerabilities makes it a liability for compliance and security.

Shame score — Microsoft shipped an unsupported, end-of-life product with a known critical vulnerability that was actively exploited in the wild, reflecting severe negligence in product lifecycle management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized