CVE-2013-0029
Description
A use-after-free in Internet Explorer 6-9 lets remote attackers execute arbitrary code via a crafted site that accesses a deleted object.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A use-after-free in Internet Explorer 6-9 lets remote attackers execute arbitrary code via a crafted site that accesses a deleted object.
Vulnerability
A use-after-free vulnerability exists in the CHTML object of Microsoft Internet Explorer 6 through 9 [1]. The bug allows a remote attacker to trigger access to a deleted object in memory via a crafted web page [2]. Affected versions are Internet Explorer 6, 7, 8, and 9 on Windows clients and servers [1].
Exploitation
An attacker must host a specially crafted web site and convince a user to view it (typically via a link in an email or instant message) [1]. No authentication or special privileges are required; the attacker only needs to craft a page that triggers the use-after-free condition, leading to memory corruption that can be leveraged for code execution [2].
Impact
Successful exploitation allows remote code execution in the context of the current user [1]. An attacker could install programs, view/change/delete data, or create new accounts with full user rights [1]. Users with fewer administrative rights are less impacted than those with administrative privileges [1].
Mitigation
Microsoft released security update MS13-009 (KB2792100) on February 12, 2013, addressing this vulnerability for Internet Explorer 6 through 10 [1]. All affected versions are patched via that cumulative update [1]. Customers with automatic updating enabled received it automatically; manual installation is recommended otherwise [1]. No workaround or KEV listing has been published.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
5cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:internet_explorer:8:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:internet_explorer:9:*:*:*:*:*:*:*
- (no CPE)range: 6 - 9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.us-cert.gov/cas/techalerts/TA13-043B.htmlnvdThird Party AdvisoryUS Government Resource
- docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-009nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16245nvd
News mentions
0No linked articles in our index yet.