VYPR
High severity7.5NVD Advisory· Published Feb 13, 2013· Updated Apr 29, 2026

CVE-2013-0029

CVE-2013-0029

Description

A use-after-free in Internet Explorer 6-9 lets remote attackers execute arbitrary code via a crafted site that accesses a deleted object.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A use-after-free in Internet Explorer 6-9 lets remote attackers execute arbitrary code via a crafted site that accesses a deleted object.

Vulnerability

A use-after-free vulnerability exists in the CHTML object of Microsoft Internet Explorer 6 through 9 [1]. The bug allows a remote attacker to trigger access to a deleted object in memory via a crafted web page [2]. Affected versions are Internet Explorer 6, 7, 8, and 9 on Windows clients and servers [1].

Exploitation

An attacker must host a specially crafted web site and convince a user to view it (typically via a link in an email or instant message) [1]. No authentication or special privileges are required; the attacker only needs to craft a page that triggers the use-after-free condition, leading to memory corruption that can be leveraged for code execution [2].

Impact

Successful exploitation allows remote code execution in the context of the current user [1]. An attacker could install programs, view/change/delete data, or create new accounts with full user rights [1]. Users with fewer administrative rights are less impacted than those with administrative privileges [1].

Mitigation

Microsoft released security update MS13-009 (KB2792100) on February 12, 2013, addressing this vulnerability for Internet Explorer 6 through 10 [1]. All affected versions are patched via that cumulative update [1]. Customers with automatic updating enabled received it automatically; manual installation is recommended otherwise [1]. No workaround or KEV listing has been published.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

5
  • cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*
    • (no CPE)range: 6 - 9

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.