LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2013-7331: Microsoft Internet Explorer Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2013-7331 to its Known Exploited Vulnerabilities catalog on May 25, 2022, with a federal patch deadline of Jun 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware…

CVE-2013-7331 is an information disclosure vulnerability in Microsoft Internet Explorer. It allows an attacker to query resources that have been loaded into memory, which can reveal the presence of anti-malware applications on the system. For IT and security teams this matters because knowledge of installed security tools can help an attacker tailor follow-on activity, evade detection, or choose more effective payloads. Confirm all product and update details against the vendor advisory.

How it works

The weakness is classified as CWE-200 (information exposure). In this case, Internet Explorer permits querying of resources that have been loaded into memory. An attacker who can cause the browser to process crafted content may obtain information about those in-memory resources. The CISA summary notes that this can allow detection of anti-malware applications. No further exploit mechanics are provided in the available facts; treat the issue as a browser-based information leak that reduces the secrecy of local security posture and confirm exact attack preconditions in the vendor advisory.

Am I affected? How to find it in your systems

Microsoft Internet Explorer is the affected product. It has historically run on Windows endpoints and servers where the browser is installed or enabled, including user workstations, terminal servers, and any systems that still rely on IE or the Trident engine for legacy web content or ActiveX controls.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability, following the vendor instructions referenced by CISA (“Apply updates per vendor instructions”). Confirm the exact KB or cumulative update package in the official advisory before deployment.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities can lead to broader compromise even when the initial flaw is only information disclosure, because the knowledge gained may enable evasion or targeted follow-on attacks. Ransomware use is not documented for this CVE in the provided facts. If you suspect exploitation, follow your incident-response process: isolate affected hosts, preserve memory and disk evidence, and hunt for secondary payloads or persistence. As a simple additional check, you can run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Internet Explorer
WeaknessCWE-200
Added to CISA KEVMay 25, 2022
Federal patch deadlineJun 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities