보안뉴스 아카이브
긴급도 83/100 심각도 8.8 · 높음 악용확률 99.5% CISA KEV · 2022-03-03 CWE-416

CVE-2013-3897

CISA 기관 조치 기한: 2022-03-24

Microsoft Internet Explorer

Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability."
KEV 필수 조치: Apply updates per vendor instructions.

벡터: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

공개 익스플로잇 / PoC

NVD 상세 ↗   벤더 권고문 ↗   참고 링크 ↗

← 취약점 목록