← Back to browse · API

CVE-2013-7331

Severity
MEDIUM
CVSS
6.5
EPSS
0.58023
Risk score
71.31
CISA KEV
Yes
PoC
No
Published
2014-02-26
Modified
2025-10-22
First seen
2026-08-07
Aliases
EUVD-2013-7105, GHSA-FPRC-FR29-2QMP
Products
Microsoft:Internet Explorer, n/a:n/a n/a
Sources
cisa.gov CVE-2013-7331
euvd EUVD-2013-7105

Description

The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a res:// URL, and exploited in the wild in February 2014.

References