CVE-2013-3893
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- June 03, 2013
- Published Date
- September 18, 2013
- Last Updated
- October 22, 2025
- Vendor
- n/a
- Product
- n/a
- Description
- Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll.
- Tags
- Exploitation
- active
- Technical Impact
- total
- Exploited in the Wild
- Yes (2026-06-01 10:38:43 UTC) Source
cisa
CVSS Scores
CVSS v3.1
8.8 - HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
9.3
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
SSVC Information
Exploit Status
References
http://jvndb.jvn.jp/ja/contents/2013/JVNDB-2013-000093.html
http://jvn.jp/en/jp/JVN27443259/index.html
http://blogs.technet.com/b/srd/archive/2013/10/08/ms13-080-addresses-two-vulnerabilities-under-limited-targeted-attacks.aspx
http://www.securityfocus.com/bid/62453
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18665
http://www.us-cert.gov/ncas/alerts/TA13-288A
http://technet.microsoft.com/security/advisory/2887505
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-080
http://pastebin.com/raw.php?i=Hx1L5gu6
http://blogs.technet.com/b/srd/archive/2013/09/17/cve-2013-3893-fix-it-workaround-available.aspx
http://packetstormsecurity.com/files/162585/Microsoft-Internet-Explorer-8-SetMouseCapture-Use-After-Free.html
Known Exploited Vulnerability Information
| Source | Added Date |
|---|---|
| CVE | 2026-06-01 10:38:43 UTC |
Scanner Integrations
| Scanner | URL | Date Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ie_setmousecapture_uaf.rb | 2025-04-28 15:02:39 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
ie_setmousecapture_uaf
Type: metasploit • Created: Unknown
Metasploit module for CVE-2013-3893
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Detected by Metasploit
-
Added to KEVIntel