Vulnerability record · CVE-2013-3205 · published 11 September 2013
CVE-2013-3205: Internet Explorer 6-8 Memory Corruption Remote Code Execution
Microsoft · Internet Explorer
Internet Explorer 6 through 8 contains a memory corruption flaw (CWE-119) that a remote attacker can trigger with a crafted web page. Successful exploitation allows arbitrary code execution or a denial of service. The vulnerability is old but still carries a high EPSS score, indicating continued attempted exploitation in the wild.
Description
Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 9.3 and very high EPSS indicate severe impact and likely exploitation, though the affected software is legacy and no KEV listing exists.
What it is
Internet Explorer 6 through 8 contains a memory corruption flaw (CWE-119) that a remote attacker can trigger with a crafted web page. Successful exploitation allows arbitrary code execution or a denial of service. The vulnerability is old but still carries a high EPSS score, indicating continued attempted exploitation in the wild.
Impact
An attacker can execute arbitrary code in the context of the logged-on user or crash the browser, leading to full system compromise or denial of service.
Attack surface
Reached over the network via a crafted website; no authentication is required, but the victim must visit the malicious page or be redirected to it (user interaction).
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is 0.66277 (99.2nd percentile), suggesting a high likelihood of exploitation attempts.
What to do
- Apply Microsoft security bulletin MS13-069 immediately.
- Upgrade to a supported version of Internet Explorer or a modern browser.
- Disable or restrict use of Internet Explorer 6, 7, and 8 where possible.
- Enforce network-level filtering and browser hardening to block known exploit patterns.
Detection
- Monitor for crashes or unexpected process terminations in iexplore.exe.
- Look for outbound connections to known malicious or suspicious domains from Internet Explorer.
- Use endpoint detection to flag memory corruption exploitation attempts against IE processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-3205 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-3205), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.