CVE-2013-2552
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/03/2013
Last modified:
11/04/2025
Description
Unspecified vulnerability in Microsoft Internet Explorer 10 on Windows 8 allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a Medium integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:microsoft:internet_explorer:10:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows_8:-:-:x64:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows_8:-:-:x86:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157
- http://twitter.com/VUPEN/statuses/309479075385327617
- http://twitter.com/thezdi/statuses/309452625173176320
- http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157
- http://twitter.com/VUPEN/statuses/309479075385327617
- http://twitter.com/thezdi/statuses/309452625173176320



