Skip to content
COOEY

EXPOSURES › CVE-2013-7331

CVE-2013-7331

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2013-7331 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

An information disclosure vulnerability in Internet Explorer allowed attackers to detect anti-malware applications by querying resources loaded into memory.

Internet Explorer's end-of-life status and history of critical vulnerabilities make this a significant concern for DIB organizations still relying on legacy systems. The vulnerability's inclusion in CISA's KEV catalog confirms it is actively exploited in the wild, increasing the risk of targeted attacks. Organizations should immediately replace Internet Explorer with modern, supported browsers to mitigate exposure to known exploits.

Shame score — The vulnerability was actively exploited in the wild and is part of CISA's KEV catalog, indicating a high level of avoidability and ongoing threat to systems still using this end-of-life product.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware applications.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized