Vulnerability record · CVE-2013-0025 · published 13 February 2013
CVE-2013-0025: Internet Explorer 8 use-after-free allows remote code execution
Microsoft · Internet Explorer
Microsoft Internet Explorer 8 contains a use-after-free flaw (SLayoutRun) where a crafted web page triggers access to a deleted object. Successful exploitation lets a remote attacker run arbitrary code in the context of the browsing user, making it a serious client-side risk for unpatched IE8 systems.
Description
Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SLayoutRun Use After Free Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution in a widely deployed browser with a high EPSS score, though the product is legacy and no KEV listing confirms active exploitation.
What it is
Microsoft Internet Explorer 8 contains a use-after-free flaw (SLayoutRun) where a crafted web page triggers access to a deleted object. Successful exploitation lets a remote attacker run arbitrary code in the context of the browsing user, making it a serious client-side risk for unpatched IE8 systems.
Impact
An attacker can execute arbitrary code with the privileges of the logged-on user, potentially leading to full system compromise. Typical outcomes include data theft, malware installation, or further lateral movement from the victim host.
Attack surface
Reached over the network via a crafted web site viewed in Internet Explorer 8; no authentication is required, but the victim must visit the malicious page or a compromised site hosting the exploit. The CVSS vector AV:N/AC:M/Au:N indicates medium attack complexity and no authentication.
Exploitation
Not listed in CISA KEV and no public exploit tags appear in the references, but EPSS is 0.55765 (99th percentile), indicating a high modeled likelihood of exploitation activity. The record does not confirm in-the-wild exploitation.
What to do
- Apply Microsoft security bulletin MS13-009, which addresses this vulnerability, or upgrade to a supported Internet Explorer version.
- Retire or isolate Internet Explorer 8 where it cannot be patched.
- Enforce EMET or equivalent exploit mitigations on legacy IE8 endpoints as a stopgap.
- Restrict browsing to trusted sites and block known malicious domains at the network edge.
- Disable or remove unnecessary IE8 components and ActiveX controls to reduce the attack surface.
Detection
- Monitor for IE8 crashes or abnormal process terminations that may indicate use-after-free exploitation attempts.
- Hunt for suspicious child processes spawned by iexplore.exe, such as script interpreters or command shells.
- Review proxy and DNS logs for access to newly registered or low-reputation domains serving exploit pages.
- Correlate endpoint telemetry for memory corruption indicators in IE8 processes with subsequent payload execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-0025 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-0025), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.