Netskope Threat Labs

BROWSER-IE Microsoft Internet Explorer CDispNode float css element use after free attempt

IPS-SWG

1 SID: 26630

First seen
February 2022
Last seen
October 2026

Detects web content that exploits CVE-2013-1309, a use-after-free in Internet Explorer's handling of floated elements that can allow code execution. The rule matches the zoom and float styling with history navigation that public exploits use to free display nodes while they remain in use.