EXPOSURES › CVE-2013-3897
CVE-2013-3897
HIGH ⌖ ON CISA KEV · EXPLOITEDA use-after-free vulnerability in Internet Explorer allowed remote code execution, and the browser was already end-of-life and unsupported.
Internet Explorer's use-after-free flaw in CDisplayPointer enabled remote code execution, a risk compounded by the browser's end-of-life status and lack of patches. DIB organizations must avoid unsupported software like IE, as its history of critical vulnerabilities makes it a liability for compliance and security.
Shame score — Microsoft shipped an unsupported, end-of-life product with a known critical vulnerability that was actively exploited in the wild, reflecting severe negligence in product lifecycle management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |