Description
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-1309.
In plain language
AI Act nowCVE-2013-2551 is a serious Internet Explorer browser bug where a specially made website could let attackers run code on your PC; if you still use Internet Explorer 6–10, you should act urgently and install the Microsoft fix.
CVE-2013-2551 is a confirmed, actively used-in-the-wild use-after-free flaw in Microsoft Internet Explorer that can be triggered by visiting a crafted website, allowing remote code execution; CISA added it to the KEV list with a remediation deadline of 2022-04-18.
What to do now
- Check whether any business device still uses Microsoft Internet Explorer 6, 7, 8, 9, or 10.
- If it’s in use, confirm the Microsoft update for MS13-037 is installed on that device.
- Upgrade away from Internet Explorer where possible (use a modern browser) and disable Internet Explorer for everyday browsing.
- If you cannot remove Internet Explorer immediately, apply the vendor remediation described in MS13-037 as the priority fix.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2013-2551 and every CVE in our database. Create a free account — no credit card required.
Create Free Account