Vulnerability record · CVE-2013-1347 · published 5 May 2013
CVE-2013-1347: Internet Explorer 8 memory object handling use-after-free RCE
Microsoft · Internet Explorer
Microsoft Internet Explorer 8 mishandles objects in memory, allowing remote code execution when an object that was not properly allocated or was deleted is accessed. It matters because the flaw was exploited in the wild in May 2013 and remains in CISA's Known Exploited Vulnerabilities catalog.
Description
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw is remotely reachable, allows arbitrary code execution, was exploited in the wild, and is listed in CISA KEV with a past remediation due date.
What it is
Microsoft Internet Explorer 8 mishandles objects in memory, allowing remote code execution when an object that was not properly allocated or was deleted is accessed. It matters because the flaw was exploited in the wild in May 2013 and remains in CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker can execute arbitrary code in the context of the affected browser process, giving full control of the user's session and data. CVSS 3.1 scores it 8.8 (HIGH) with high confidentiality, integrity and availability impact.
Attack surface
Reached over the network via a crafted web page that triggers the memory handling flaw; the CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates no authentication is needed but user interaction, such as visiting the page, is required.
Exploitation
Exploitation is confirmed: the description states it was exploited in the wild in May 2013, CISA KEV lists it with a 2022-03-24 remediation due date, and an Exploit-DB entry exists. EPSS gives a 30-day probability of 0.77889 (99.5th percentile).
What to do
- Apply the Microsoft update referenced in MS13-038 and security advisory 2847140, or upgrade off Internet Explorer 8 entirely.
- Enforce the vendor mitigations from advisory 2847140 for systems that cannot be patched immediately.
- Restrict or block use of Internet Explorer 8 for general web browsing and route users to a supported browser.
- Apply the CISA KEV required action and track remediation against the 2022-03-24 due date.
- Limit privileged browsing and apply defense-in-depth controls such as EMET or exploit protection where legacy IE 8 must remain.
Detection
- Hunt for Internet Explorer 8 processes spawning child processes or making unexpected network connections, which can indicate post-exploitation activity.
- Monitor for crashes or abnormal termination of iexplore.exe consistent with use-after-free exploitation attempts.
- Review proxy and DNS logs for known exploit-hosting domains and for users reaching pages tied to this campaign.
- Alert on execution of known Exploit-DB 25294 payload patterns or related indicators in endpoint telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2013-1347 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Internet Explorer Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-1347 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-1347), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.