CVE-2013-0025
Microsoft Internet Explorer 8 - Remote Code Execution via SLayoutRun Use-After-Free
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2013-0025.
PoCs published by Metasploit, Scott Bell, including Metasploit module exploits/windows/browser/ms13_009_ie_slayoutrun_uaf.
AI-analyzed exploit summary This Metasploit module exploits a use-after-free vulnerability in Microsoft Internet Explorer (CVE-2013-0025) by manipulating a CParaElement node and performing a heap spray to achieve remote code execution.
Description
Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SLayoutRun Use After Free Vulnerability."
Exploits (3)
This Metasploit module exploits a use-after-free vulnerability in Microsoft Internet Explorer (CVE-2013-0025) by manipulating a CParaElement node and performing a heap spray to achieve remote code execution.
This Metasploit module exploits a use-after-free vulnerability in Microsoft Internet Explorer (CVE-2013-0025) by manipulating a CParaElement node and performing heap spraying to achieve remote code execution.
This Metasploit module exploits a use-after-free vulnerability in Microsoft Internet Explorer (CVE-2013-0025) by manipulating a CParaElement node reference in CDoc, leading to remote code execution via heap spraying and ROP chains.