Back
CVE-2013-3897
HIGH
CISA KEV
Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability."
Published: Oct 9, 2013
Modified: Apr 22, 2026
CWE-416
CWE-416
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
REQUIRED
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products (6)
| Vendor | Product | Version |
|---|---|---|
| microsoft | internet_explorer | 6 |
| microsoft | internet_explorer | 7 |
| microsoft | internet_explorer | 8 |
| microsoft | internet_explorer | 9 |
| microsoft | internet_explorer | 10 |
| microsoft | internet_explorer | 11 |
References (9)
- http://blogs.technet.com/b/srd/archive/2013/10/08/ms13-080-addresses-two-vulnerabilities-under-limited-targeted-attacks.aspx Broken Link, Vendor Advisory
- http://www.us-cert.gov/ncas/alerts/TA13-288A Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-080 Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18989 Broken Link
- http://blogs.technet.com/b/srd/archive/2013/10/08/ms13-080-addresses-two-vulnerabilities-under-limited-targeted-attacks.aspx Broken Link, Vendor Advisory
- http://www.us-cert.gov/ncas/alerts/TA13-288A Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-080 Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18989 Broken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-3897 US Government Resource
Risk Scores
CVSS Score
8.8 / 10
EPSS Score
77.46%
Top 1% most likely to be exploited
Threat Score
88.4 / 100
CISA Known Exploited
Date Added:
2022-03-03
Due Date:
2022-03-24
Required Action:
Apply updates per vendor instructions.
Data Sources
NVD
CISA KEV
EPSS