CVE-2013-3893 is a use-after-free vulnerability in Internet Explorer 6-11 that allows remote code execution via crafted JavaScript when a user visits a malicious website. This is a client-side browser vulnerability requiring user interaction, not a server-side vulnerability.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: USER_INTERACTION
CVE Published: 2013-09-18
Added to CISA KEV: 2025-08-12 4346 DAYS BETWEEN CVE AND KEV
CVE-2013-3893 is a critical use-after-free vulnerability in the `SetMouseCapture` implementation within `mshtml.dll`, a core component of Microsoft Internet Explorer [1].
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute ... http://blogs.technet.com/b/srd/archive/2013/09/17/cve-2013-3893-fix-it-workaround-available.aspx. CVE, Microsoft Corporation. Exploit. hβ¦
Today, we released a Fix it workaround tool to address a new IE vulnerability that had been actively exploited in extremely limited, targeted attacks. This Fix it makes a minor modification to mshtml.dll when it is loaded in memory to address the vulnerability. This Fix it workaround tool is linkedβ¦
Executive Summary. We have seen the CVE-2013-3893 exploit targeting Japanese firms in the financial industry hosted on a Taiwanese IP address. Our ThreatSeeker Intelligence Cloud reported a potential victim organization in Taiwan attempting to communicate with the associated malicious command and coβ¦