CVE-2013-0025

Microsoft Internet Explorer - Resource Management Error

Title source: rule

Description

Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SLayoutRun Use After Free Vulnerability."

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/24538
exploitdb WORKING POC VERIFIED
by Scott Bell · rubyremotewindows
https://www.exploit-db.com/exploits/24495
metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ms13_009_ie_slayoutrun_uaf.rb

Scores

EPSS 0.8605
EPSS Percentile 99.4%

Details

CWE
CWE-399
Status published
Products (1)
microsoft/internet_explorer 8
Published Feb 13, 2013
Tracked Since Feb 18, 2026