Overview
Microsoft Internet Explorer 8 contains a use-after-free vulnerability in the CGenericElement object, which is currently being exploited in the wild.
Description
| Microsoft Security Advisory 2847140 states: Internet Explorer 6, Internet Explorer 7, Internet Explorer 9, and Internet Explorer 10 are not affected by the vulnerability. | 
Impact
| A remote unauthenticated attacker may be able to run arbitrary code in the context of the user running Internet Explorer 8. | 
Solution
| Apply an Update | 
| Apply a Microsoft "Fix It" | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | 9.4 | AV:N/AC:L/Au:N/C:C/I:C/A:N | 
| Temporal | 8.9 | E:H/RL:W/RC:C | 
| Environmental | 6.7 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND | 
References
- https://technet.microsoft.com/en-us/security/bulletin/ms13-038
- http://blogs.technet.com/b/srd/archive/2013/05/08/microsoft-quot-fix-it-quot-available-to-mitigate-internet-explorer-8-vulnerability.aspx
- http://technet.microsoft.com/en-us/security/advisory/2847140
- http://blogs.technet.com/b/msrc/archive/2013/05/03/microsoft-releases-security-advisory-2847140.aspx
- https://community.rapid7.com/community/metasploit/blog/2013/05/05/department-of-labor-ie-0day-now-available-at-metasploit
- http://dev.metasploit.com/redmine/projects/framework/repository/revisions/a33510e82135355548a529e5f0cb5ab7134d674d/entry/modules/exploits/windows/browser/ie_cgenericelement_uaf.rb
- http://labs.alienvault.com/labs/index.php/2013/u-s-department-of-labor-website-hacked-and-redirecting-to-malicious-code/
Acknowledgements
This vulnerability was discovered in the wild.
This document was written by Jared Allar.
Other Information
| CVE IDs: | CVE-2013-1347 | 
| Date Public: | 2013-05-03 | 
| Date First Published: | 2013-05-06 | 
| Date Last Updated: | 2013-05-14 17:28 UTC | 
| Document Revision: | 29 |