Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2013-7331

The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a res:// URL, and exploited in the wild in February 2014.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.856
EPSS Ranking 99.3%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.3
Proposed Action
An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware applications.
Ransomware Campaign
Unknown
References
Products affected by CVE-2013-7331


Contact Us

Shodan ® - All rights reserved