CVE-2013-2551
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Mar 11, 2013
Updated: Dec 20, 2024
CWE ID 416
Summary
CVE-2013-2551 is a use-after-free vulnerability affecting Microsoft Internet Explorer 6 to 10. This issue allows remote attackers to execute arbitrary code by manipulating a webpage to access a deleted object. This vulnerability was publicly disclosed during the Pwn2Own competition at CanSecWest 2013 and should not be confused with CVE-2013-1308 and CVE-2013-1309, which are separate issues. VUPEN Security demonstrated the exploit during the competition.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Internet Explorer
Affected Vendors
- Microsoft