CVE-2013-3893
HIGH KEVMicrosoft Internet Explorer 6-11 - Remote Code Execution via SetMouseCapture Use-After-Free
Title source: llmExploitation Summary
CVE-2013-3893 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added August 12, 2025.
EIP tracks 4 public exploits from researchers including Metasploit, SlidingWindow, Unknown, sinn3r, Rich Lundeen, including a Metasploit module exploits/windows/browser/ie_setmousecapture_uaf.
AI-analyzed exploit summary This Metasploit module exploits a use-after-free vulnerability in Internet Explorer (CVE-2013-3893) by manipulating the `SetMouseCapture` function to achieve arbitrary code execution. It targets IE 9 on Windows 7 SP1, leveraging Microsoft Office DLLs (2007/2010) for ROP chains.
Description
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll.
Exploits (4)
This Metasploit module exploits a use-after-free vulnerability in Internet Explorer (CVE-2013-3893) by manipulating the `SetMouseCapture` function to achieve arbitrary code execution. It targets IE 9 on Windows 7 SP1, leveraging Microsoft Office DLLs (2007/2010) for ROP chains.
This is a functional exploit for CVE-2013-3893, a use-after-free vulnerability in Microsoft Internet Explorer 8. It leverages heap spraying and ROP chains to bypass DEP and ASLR, ultimately achieving remote code execution via a reverse shell payload.
This Metasploit module exploits a use-after-free vulnerability in Internet Explorer (CVE-2013-3893) by manipulating the `SetMouseCapture` function to trigger arbitrary memory release and subsequent code execution. It leverages ROP chains and heap spraying to achieve reliable exploitation on targeted IE versions.
The repository contains a JavaScript file for formatting pre blocks and handling scroll events, which is unrelated to CVE-2013-3893. No exploit code or technical details about the vulnerability are present.
References (12)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H