CVE Tools

Description

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-1309.

In plain language

AI Act now

CVE-2013-2551 is a serious Internet Explorer browser bug where a specially made website could let attackers run code on your PC; if you still use Internet Explorer 6–10, you should act urgently and install the Microsoft fix.

Executive summary

CVE-2013-2551 is a confirmed, actively used-in-the-wild use-after-free flaw in Microsoft Internet Explorer that can be triggered by visiting a crafted website, allowing remote code execution; CISA added it to the KEV list with a remediation deadline of 2022-04-18.

If affected, business impact
Full control of workstationMalware installationRansomware infection riskData theft from compromised PC

What to do now

  1. Check whether any business device still uses Microsoft Internet Explorer 6, 7, 8, 9, or 10.
  2. If it’s in use, confirm the Microsoft update for MS13-037 is installed on that device.
  3. Upgrade away from Internet Explorer where possible (use a modern browser) and disable Internet Explorer for everyday browsing.
  4. If you cannot remove Internet Explorer immediately, apply the vendor remediation described in MS13-037 as the priority fix.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:RS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 1 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Mar 28, 2022
Remediation due:Apr 18, 2022
Ransomware:Known ransomware use

Required action: Apply updates per vendor instructions.

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Initial Access
Privilege Escalation
View detailed technique mapping

References

and 4 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2013-2551 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows