CVE-2013-7331
MEDIUMThe Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames,…
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a res:// URL, and exploited in the wild in February 2014.
Affected Products
internet explorermicrosoftResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlie…
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlie…
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlie…
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlie…
Frequently Asked Questions
Is CVE-2013-7331 in your stack?
O3 detects CVE-2013-7331 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.