Skip to main content

CVE detail

CVE-2013-3893

Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll.

CVSS 8.8 · HighBuzz score 66.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 66.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 11.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
22 evidence mentions in the snapshot
Diversity score
11.0
5 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
22 source links · newest first
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Internet Explorer, Microsoft Office Excel, and WinRAR flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Microsoft Internet Explorer, Microsoft Office Excel, and WinRAR flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws: According […]

    newssecurityaffairs.comAug 14, 2025, 12:12 AM
  • The Japanese Government is investigating a reported security breach suffered by the High-speed Defence Information Infrastructure (DII) network. The Defence Information Infrastructure is a high-speed large-capacity communication network connecting SDF bases and camps. The Defence Information Infrastructure comprises two distinct networks, one connected to the Internet and an internal network. The security breach took place […]

    newssecurityaffairs.comNov 28, 2016, 1:42 PM
  • New research from FireEye shows that the Asia-Pacific region was twice as likely to be targeted by advanced persistent threats during 2013 than the rest of the world.

    newswww.securityweek.comJan 15, 2014, 10:42 PM
  • Why do we need for Incident Response plan?Security Affairs

    Due to the constant growth in the number of cyber attacks it is necessary to properly define the actions composing an incident response plan. FireEye firm published an interesting post on the need of incident response (IR) capabilities to reply numerous cyber attacks that daily hit almost any web service. Starting from the data proposed […]

    newssecurityaffairs.comNov 26, 2013, 7:58 PM
  • Attackers are increasingly dodging the address space layout randomization [ASLR] mechanisms used to thwart buffer overflow attacks.

    newswww.securityweek.comOct 15, 2013, 9:34 PM
  • Here’s an overview of some of last week’s most interesting news, videos, interviews and articles: How to establish trust in the cloud In order to enforce corporate security policies in the cloud, IT needs to know (1) who is accessing and sharing (2) what documents (3) in which cloud storage service, and (4) that the cloud provider cannot override policies established by the business or access the data itself. Vulnerable and aggressive adware threatening millions … More →

    newswww.helpnetsecurity.comOct 14, 2013, 12:00 AM
  • Security researchers say a previously undisclosed Internet Explorer zero-day patched by Microsoft this week has been actively used in targeted attacks since at least September.

    newswww.securityweek.comOct 10, 2013, 7:48 PM
  • With this month’s Patch Tuesday, Microsoft has delivered the patch for the infamous Internet Explorer zero-day (CVE-2013-3893) that has been spotted being used in attacks that date as back as three or four months ago and have been tied to the Chinese hacking group that hit Bit9 earlier this year. What has received a little less attention is that a patch for another IE zero-day actively exploited in the wild has been released simultaneously: CVE-2013-3897. … More →

    newswww.helpnetsecurity.comOct 10, 2013, 9:33 AM
  • Microsoft released eight security bulletins – including four rated Critical – to address 26 vulnerabilities in Windows, Internet Explorer and other products in this month’s Patch Tuesday.

    newswww.securityweek.comOct 8, 2013, 7:08 PM
  • Microsoft exceedes 100 bulletins for 2013Help Net Security

    It’s been an interesting month for the Microsoft Security watchers of the world. If your job depends on securing systems running Windows, you should be eagerly awaiting the patch for the Internet Explorer (IE) 0-day (CVE-2013-3893: SetMouseCapture Use-After-Free) vulnerability in today’s Patch Tuesday (MS13-080). Exploitation of this vulnerability was detected first in targeted, regionally restricted exploitation, and then later in broader use once the exploit code spread to various public sites. Hopefully users have applied … More →

    newswww.helpnetsecurity.comOct 8, 2013, 2:54 PM
  • Here’s an overview of some of last week’s most interesting news, videos, interviews and articles: The impact of false positives on web application security scanners Ferruh Mavituna is the CEO at Mavituna Security and the Product Architect of Netsparker. In this interview he discusses what impact false positives have on web application security scanners and what his team is doing to deliver false positive free scans. Two youngsters arrested for different DDoS attacks Following the … More →

    newswww.helpnetsecurity.comOct 7, 2013, 12:00 AM
  • Microsoft to unveil eight bulletins on TuesdayHelp Net Security

    October is turning out to be a busy month for patches. Next week is Patch Tuesday, and both Adobe and Microsoft have published their advance notices, with one and eight bulletins respectively. In addition, on October 15th we are getting the Critical Patch Update from Oracle, which will include a new version for Oracle enterprise software, plus a new version of Java 7. This month also marks the 10-year anniversary of the Patch Tuesday program, … More →

    newswww.helpnetsecurity.comOct 4, 2013, 4:58 AM
  • Both security professionals and cybercriminals use Metasploit, a penetration testing toolkit maintained by Rapid7, so when a Metasploit module is released, you should expect attacks against unpatched vulnerabilities to kick into a higher gear. Yesterday, Metasploit released a module for the latest IE zero day vulnerability being exploited in the wild. Microsoft’s security advisory dated […]

    newswww.csoonline.comOct 1, 2013, 8:01 PM
  • This month marks the 10th Anniversary of National Cyber Security Awareness Month, or NCSAM, here in the United States and hopefully…

    newswww.malwarebytes.comSep 30, 2013, 5:00 PM
  • While Microsoft is yet to issue a patch for the latest Internet Explorer zero-day (CVE-2013-3893), reports are coming in that the flaw has been exploited more widely and for a longer time than initially believed. Microsoft acknowledged the existence of the vulnerability and its active exploitation earlier this month, and has issued a Fix it tool to mitigate the danger until a patch can be released. Since then, FireEye researchers have tied the attacks to … More →

    newswww.helpnetsecurity.comSep 30, 2013, 8:59 AM
  • Here’s an overview of some of last week’s most interesting news, reviews and articles: IE 0-day attack reports push ISC to raise official threat level FireEye researchers have managed to shed some light on the in-the-wild attacks leveraging the latest discovered Internet Explorer zero-day vulnerability (CVE-2013-3893), and have tracked it back to the Chinese hacking group that hit Bit9 earlier this year. Free guide to iOS 7 The new version of iOS marks a notable … More →

    newswww.helpnetsecurity.comSep 30, 2013, 12:00 AM
  • Security experts at FireEye discovered the Operation DeputyDog against Japanese entities that exploits Zero-Day (CVE-2013-3893) recently announced by Microsoft. FireEye announced the discovery of the cyberespionage Operation DeputyDog leveraging the recently announced zero-day CVE-2013-3893. FireEye and Kaspersky are the companies most active in the analysis of large espionage campaign that governments and hackers are conducting against strategic targets. According the analysis based on FireEye […]

    newssecurityaffairs.comSep 24, 2013, 6:31 AM
  • Over the weekend, FireEye researchers have managed to shed some light on the in-the-wild attacks leveraging the latest discovered Internet Explorer zero-day vulnerability (CVE-2013-3893), and have tracked it back to the Chinese hacking group that hit Bit9 earlier this year. According to their research, the campaign – dubbed DeputyDog – has been targeting Japanese organizations since August August 19, 2013, and the attackers have been using a C&C infrastructure that is related to the infrastructure … More →

    newswww.helpnetsecurity.comSep 23, 2013, 9:41 AM
  • According to Microsoft, a zero day flaw in Internet Explorer (IE) , which impacts all versions of the browser, is being actively exploited in the wild. Reports of exploitation, according to Microsoft, seem to have criminals focused on IE versions 8 and 9. Complicating matters, researchers at Websense have discovered that nearly 70 percent of […]

    newswww.csoonline.comSep 19, 2013, 3:00 PM
  • Microsoft announced to be aware of a new IE Zero Day vulnerability (CVE-2013-3893) that affects Windows browsers IE 8 and IE 9 recently targeted by hackers. Microsoft announced to be aware of the presence of a zero-day vulnerability (CVE-2013-3893) in its browser IE. Windows browsers IE 8 and IE 9 are affected by serious zero-day vulnerability recently targeted […]

    newssecurityaffairs.comSep 18, 2013, 7:26 AM
  • Microsoft pushed out an emergency Fix It tool to close a security vulnerability being exploited in attacks against Internet Explorer 8 and 9.

    newswww.securityweek.comSep 17, 2013, 9:08 PM
  • Microsoft releases fix for IE Zero-DayMalwarebytes Labs

    Microsoft disclosed information on a new Internet Explorer zero-day vulnerability yesterday in a security advisory.Dubbed CVE-2013-3893, the vulnerability exists in SetMouseCapture…

    newswww.malwarebytes.comSep 17, 2013, 5:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence