Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Vulnerability protection

Internet Explorer cumulative security update


Report ID: MS201305001
Date Published: 15 May 2013

Criticality: Critical
Compromise Type: remote-code-execution information-disclosure
Compromise From: remote


Affected Product/Component:

Internet Explorer 6
Internet Explorer 7
Internet Explorer 8
Internet Explorer 9
Internet Explorer 10




Summary

A cumulative security update for Internet Explorer has been released to address eleven reported vulnerabilities, ten of which could lead to remote code execution and one could lead to information disclosure.



Detailed Description

Microsoft has released a cumulative security update for Internet Explorer (IE) to address eleven reported vulnerabilities. Ten of those are remote code execution vulnerabilities that existed when attempting to access a deleted object in memory, while the other one is an information disclosure vulnerability that was caused by a flaw in allowing VBScript to read JSON data files. 

All of the vulnerabilities have been patched in the latest security update by modifying the way IE handles objects in memory and the way IE authorizes script access to data. Users are recommended to install the latest update to their system as a protection measure against possible exploit attempts.



CVE Reference

CVE-2013-0811, CVE-2013-1306, CVE-2013-1307, CVE-2013-1308, CVE-2013-1309, CVE-2013-1310, CVE-2013-1311, CVE-2013-1312, CVE-2013-1313, CVE-2013-2551, CVE-2013-1297



Solution

Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms13-037)



Security Advisories

For a list of known vulnerabilities affecting F-Secure products and the released fixes, please refer to the Security Advisories page.