Internet Explorer 8 0-Day Update CVE-2013-1347
Microsoft has confirmed a bug in Internet Explorer 8, CVE-2013-1347, which exposes user machines to remote code execution. In an advisory, Microsoft says the vulnerability âexists in the way that Internet Explorer [accesses] an object in memory that has been deleted or has not been properly allocated.â That, in turn, opens the door to memory corruption and remote code execution in the current user context. According to this blog post by Eric Roman: âA use-after-free condition occurs when a CGenericElement object is freed, but a reference is kept on the document and used again during rendering, an invalid memory thatâs controllable is used, and allows arbitrary code execution under the context of the user.â ...