Executive Summary

Summary
Title Cumulative Security Update for Internet Explorer (2792100)
Informations
Name MS13-009 First vendor Publication 2013-02-12
Vendor Microsoft Last vendor Modification 2013-05-14
Severity (Vendor) Critical Revision 1.2

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score 9.3 Attack Range Network
Cvss Impact Score 10 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Revision Note: V1.2 (May 14, 2013): Revised this bulletin to announce a detection change to correct an offering issue for Windows Server 2012 (Server Core installation). This is a detection change only. There were no changes to the security update files. Customers who have already successfully updated their systems do not need to take any action.

Summary: This security update resolves thirteen privately reported vulnerabilities in Internet Explorer. The most severe vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited these vulnerabilities could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Original Source

Url : http://technet.microsoft.com/en-us/security/bulletin/ms13-009

CWE : Common Weakness Enumeration

% Id Name
92 % CWE-399 Resource Management Errors
8 % CWE-200 Information Exposure

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:15875
 
Oval ID: oval:org.mitre.oval:def:15875
Title: Internet Explorer CMarkup use after free vulnerability - MS13-009
Description: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CMarkup Use After Free Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2013-0020
Version: 5
Platform(s): Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows 7
Product(s): Microsoft Internet Explorer 9
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16069
 
Oval ID: oval:org.mitre.oval:def:16069
Title: Internet Explorer LsGetTrailInfo use after free vulnerability - MS13-009
Description: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer LsGetTrailInfo Use After Free Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2013-0022
Version: 5
Platform(s): Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8
Product(s): Microsoft Internet Explorer 9
Microsoft Internet Explorer 10
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16126
 
Oval ID: oval:org.mitre.oval:def:16126
Title: Internet Explorer pasteHTML use after free vulnerability - MS13-009
Description: Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer pasteHTML Use After Free Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2013-0024
Version: 5
Platform(s): Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 7
Product(s): Microsoft Internet Explorer 8
Microsoft Internet Explorer 9
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16245
 
Oval ID: oval:org.mitre.oval:def:16245
Title: Internet Explorer CHTML use after free vulnerability - MS13-009
Description: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CHTML Use After Free Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2013-0029
Version: 5
Platform(s): Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 7
Product(s): Microsoft Internet Explorer 6
Microsoft Internet Explorer 7
Microsoft Internet Explorer 8
Microsoft Internet Explorer 9
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16249
 
Oval ID: oval:org.mitre.oval:def:16249
Title: Internet Explorer CObjectElement use after free vulnerability - MS13-009
Description: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CObjectElement Use After Free Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2013-0028
Version: 5
Platform(s): Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 7
Product(s): Microsoft Internet Explorer 6
Microsoft Internet Explorer 7
Microsoft Internet Explorer 8
Microsoft Internet Explorer 9
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16294
 
Oval ID: oval:org.mitre.oval:def:16294
Title: Internet Explorer SLayoutRun use after free vulnerability - MS13-009
Description: Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SLayoutRun Use After Free Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2013-0025
Version: 5
Platform(s): Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 7
Product(s): Microsoft Internet Explorer 8
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16360
 
Oval ID: oval:org.mitre.oval:def:16360
Title: Internet Explorer CPasteCommand use after free vulnerability - MS13-009
Description: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CPasteCommand Use After Free Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2013-0027
Version: 5
Platform(s): Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 7
Microsoft Windows 8
Product(s): Microsoft Internet Explorer 6
Microsoft Internet Explorer 7
Microsoft Internet Explorer 8
Microsoft Internet Explorer 9
Microsoft Internet Explorer 10
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16371
 
Oval ID: oval:org.mitre.oval:def:16371
Title: Shift JIS character encoding vulnerability - MS13-009
Description: Microsoft Internet Explorer 6 through 9 does not properly perform auto-selection of the Shift JIS encoding, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site that triggers cross-domain scrolling events, aka "Shift JIS Character Encoding Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2013-0015
Version: 5
Platform(s): Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 7
Product(s): Microsoft Internet Explorer 6
Microsoft Internet Explorer 7
Microsoft Internet Explorer 8
Microsoft Internet Explorer 9
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16438
 
Oval ID: oval:org.mitre.oval:def:16438
Title: Internet Explorer SetCapture use after free vulnerability - MS13-009
Description: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SetCapture Use After Free Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2013-0018
Version: 5
Platform(s): Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 7
Product(s): Microsoft Internet Explorer 6
Microsoft Internet Explorer 7
Microsoft Internet Explorer 8
Microsoft Internet Explorer 9
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16465
 
Oval ID: oval:org.mitre.oval:def:16465
Title: Internet Explorer COmWindowProxy use after free vulnerability - MS13-009
Description: Use-after-free vulnerability in Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer COmWindowProxy Use After Free Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2013-0019
Version: 5
Platform(s): Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 7
Microsoft Windows 8
Product(s): Microsoft Internet Explorer 7
Microsoft Internet Explorer 8
Microsoft Internet Explorer 9
Microsoft Internet Explorer 10
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16470
 
Oval ID: oval:org.mitre.oval:def:16470
Title: Internet Explorer CDispNode use after free vulnerability - MS13-009
Description: Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CDispNode Use After Free Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2013-0023
Version: 5
Platform(s): Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8
Product(s): Microsoft Internet Explorer 9
Microsoft Internet Explorer 10
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16472
 
Oval ID: oval:org.mitre.oval:def:16472
Title: Internet Explorer InsertElement use after free vulnerability - MS13-009
Description: Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer InsertElement Use After Free Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2013-0026
Version: 5
Platform(s): Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows 7
Product(s): Microsoft Internet Explorer 9
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16483
 
Oval ID: oval:org.mitre.oval:def:16483
Title: Internet Explorer vtable use after free vulnerability - MS13-009
Description: Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer vtable Use After Free Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2013-0021
Version: 5
Platform(s): Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 7
Microsoft Windows 8
Product(s): Microsoft Internet Explorer 6
Microsoft Internet Explorer 7
Microsoft Internet Explorer 8
Microsoft Internet Explorer 9
Microsoft Internet Explorer 10
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 5
Os 3
Os 1

SAINT Exploits

Description Link
Internet Explorer SLayoutRun CParaElement Node Use After Free More info here

ExploitDB Exploits

id Description
2013-06-13 MS13-009 Microsoft Internet Explorer COALineDashStyleArray Integer Overflow
2013-02-23 MS13-009 Microsoft Internet Explorer SLayoutRun Use-After-Free
2013-02-14 Microsoft Internet Explorer SLayoutRun Use-After-Free (MS13-009)

Snort® IPS/IDS

Date Description
2018-09-11 Microsoft Internet Explorer pre-line use after free attempt
RuleID : 47463 - Revision : 2 - Type : BROWSER-IE
2017-06-06 Microsoft Internet Explorer deleted object access memory corruption attempt
RuleID : 42450 - Revision : 2 - Type : BROWSER-IE
2017-06-06 Microsoft Internet Explorer deleted object access memory corruption attempt
RuleID : 42449 - Revision : 2 - Type : BROWSER-IE
2017-06-06 Microsoft Internet Explorer deleted object access memory corruption attempt
RuleID : 42448 - Revision : 2 - Type : BROWSER-IE
2016-03-14 Microsoft Internet Explorer pre-line use after free attempt
RuleID : 36436 - Revision : 2 - Type : BROWSER-IE
2014-11-16 Microsoft Internet Explorer onbeforeeditfocus element attribute use after fre...
RuleID : 31486 - Revision : 2 - Type : BROWSER-IE
2014-11-16 Microsoft Internet Explorer onbeforeeditfocus element attribute use after fre...
RuleID : 31485 - Revision : 2 - Type : BROWSER-IE
2014-05-03 Microsoft Internet Explorer onbeforeeditfocus element attribute use after fre...
RuleID : 30345 - Revision : 3 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer 9 deleted object access memory corruption attempt
RuleID : 27717 - Revision : 2 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer 9 deleted object access memory corruption attempt
RuleID : 27716 - Revision : 2 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer CHTMLEditor object use after free attempt
RuleID : 26225 - Revision : 3 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer CHTMLEditor object use after free attempt
RuleID : 26224 - Revision : 3 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer CHTMLEditor object use after free attempt
RuleID : 26223 - Revision : 3 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer CHTMLEditor object use after free attempt
RuleID : 26222 - Revision : 3 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer CHTMLEditor object use after free attempt
RuleID : 26221 - Revision : 3 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer CHTMLEditor object use after free attempt
RuleID : 26220 - Revision : 3 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer CHTMLEditor object use after free attempt
RuleID : 26219 - Revision : 3 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer CHTMLEditor object use after free attempt
RuleID : 26218 - Revision : 3 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer CHTMLEditor object use after free attempt
RuleID : 26217 - Revision : 3 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer CHTMLEditor object use after free attempt
RuleID : 26216 - Revision : 3 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer invalid Shift_JIS character xss attempt
RuleID : 25794 - Revision : 3 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer invalid Shift_JIS character xss attempt
RuleID : 25793 - Revision : 3 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer SVG object use after free attempt
RuleID : 25792 - Revision : 4 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer compatibility mode invalid memory access attempt
RuleID : 25791 - Revision : 6 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer compatibility mode invalid memory access attempt
RuleID : 25790 - Revision : 6 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer iframe use after free attempt
RuleID : 25789 - Revision : 4 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer iframe use after free attempt
RuleID : 25788 - Revision : 7 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer 9 deleted object access memory corruption attempt
RuleID : 25787 - Revision : 4 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer 9 deleted object access memory corruption attempt
RuleID : 25786 - Revision : 4 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer text layout calculation use after free attempt
RuleID : 25785 - Revision : 3 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer text layout calculation use after free attempt
RuleID : 25784 - Revision : 3 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer SVG use after free attempt
RuleID : 25778 - Revision : 5 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer CTreePos use after free memory corruption attempt
RuleID : 25777 - Revision : 3 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer CTreePos use after free memory corruption attempt
RuleID : 25776 - Revision : 3 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer pre-line use after free attempt
RuleID : 25775 - Revision : 6 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer onbeforeeditfocus element attribute use after fre...
RuleID : 25772 - Revision : 7 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer custom cursor file use after free attempt
RuleID : 25771 - Revision : 6 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer deleted object access memory corruption attempt
RuleID : 25770 - Revision : 4 - Type : BROWSER-IE
2014-01-10 Microsoft Internet Explorer CHTMLEditor object use after free attempt
RuleID : 25769 - Revision : 5 - Type : BROWSER-IE

Metasploit Database

id Description
2013-02-13 MS13-009 Microsoft Internet Explorer SLayoutRun Use-After-Free

Nessus® Vulnerability Scanner

Date Description
2013-02-12 Name : The remote host is affected by multiple code execution vulnerabilities.
File : smb_nt_ms13-009.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
Date Informations
2020-05-23 13:17:14
  • Multiple Updates
2014-11-16 21:25:25
  • Multiple Updates
2014-05-03 21:21:15
  • Multiple Updates
2014-02-17 11:47:32
  • Multiple Updates
2014-01-19 21:30:55
  • Multiple Updates
2013-05-14 21:15:53
  • Multiple Updates
2013-05-11 00:50:06
  • Multiple Updates
2013-02-13 17:21:04
  • Multiple Updates
2013-02-13 13:21:00
  • Multiple Updates
2013-02-13 05:21:12
  • Multiple Updates
2013-02-13 05:17:47
  • Multiple Updates
2013-02-12 21:22:09
  • Multiple Updates
2013-02-12 21:18:35
  • First insertion