Skip to main content

CVE detail

CVE-2013-7331

The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a res:// URL, and exploited in the wild in February 2014.

CVSS 6.5 · MediumBuzz score 56.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 56.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 23.0 · diversity 8.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
23.0
9 evidence mentions in the snapshot
Diversity score
8.0
3 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
9 source links · newest first
  • It’s a new year and while some things change, some things stay the same (or similar). There’s lots of FUD about the sophisticated cyber attacks that are multi-threaded and obfuscated. Certainly there are attacks that fall into this category, but if you look at all of the cybercrime activity from the past year, it’s clear that the majority of threats do not have the level of sophistication that is often talked about.

    newswww.securityweek.comJan 20, 2017, 4:16 PM
  • Exploit kits: Fall 2016 reviewMalwarebytes Labs

    There have been interesting developments with exploit kits in the past few months to say the least, with the disappearance of…

    newswww.malwarebytes.comNov 8, 2016, 5:00 PM
  • Update (04/12/2017): The INRIA has a tool to fingerprint browser extensions and detect other other browser leaks.Update (03/17/2017): Microsoft patched CVE-2017-0022, reported by…

    newswww.malwarebytes.comAug 28, 2016, 5:00 PM
  • Neutrino EK: fingerprinting in a FlashMalwarebytes Labs

    Since the disappearance of Angler EK, exploit kit activity is at one of its lowest it has been in a long…

    newswww.malwarebytes.comJun 27, 2016, 5:00 PM
  • SSL Malvertising Campaign Targets Top Adult SitesMalwarebytes Labs

    The SSL malvertising campaign we documented in August that affected Yahoo.com, MSN.com and several other top sites is still ongoing. This…

    newswww.malwarebytes.comSep 24, 2015, 5:00 PM
  • Angler Exploit Kit Gives Up on Malwarebytes UsersMalwarebytes Labs

    It is a well-known fact that malware authors try really hard to avoid security researchers and their analysis tools. For instance,…

    newswww.malwarebytes.comMay 18, 2015, 5:00 PM
  • Researchers from threat protection firm Bromium were alerted last week by a customer to an attack originating from the website of a high-profile technology startup in the oil and gas sector.

    newswww.securityweek.comSep 17, 2014, 10:02 PM
  • Tucked within Microsoft’s September patch release was a fix for a vulnerability that had been used this year in a sophisticated attack aimed at stealing U.S. military secrets. A proof-of-concept (PoC) exploit for the XMLDOM vulnerability, which Microsoft labeled cve-2013-7331, was first released in April 2013. The PoC was then “re-repurposed and abused” in the […]

    newswww.csoonline.comSep 12, 2014, 12:01 AM
  • Microsoft issued a patch today for a vulnerability in Internet Explorer (IE) that has been targeted in attacks as part of its monthly Patch Tuesday update.

    newswww.securityweek.comSep 9, 2014, 7:33 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence