CVE-2013-3918
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted web page that is accessed by Internet Explorer, as exploited in the wild in November 2013, aka "InformationCardSigninHelper Vulnerability."
- Affected products
- Internet Explorer, Windows, Windows 7, Windows 8, Windows 8.1, Windows Rt, Windows Server 2003, Windows Server 2008
- Microsoft Windows 7
- All versions
- Microsoft Windows 8
- All versions
- Microsoft Windows 8.1
- All versions
- Microsoft Windows Rt
- All versions
- Microsoft Windows Rt 8.1
- All versions
- Microsoft Windows Server 2003
- All versions
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 73.9% (99th percentile)
- Weakness
- CWE-787
- NVD status
- Analyzed
- Published
- 2013-11-12
CVE-2013-3918 at NVD
5 known exploits for CVE-2013-3918
Proof-of-concept code and exploit modules indexed by Sploitus
Microsoft Internet Explorer - CardSpaceClaimCollection ActiveX Integer Underflow (MS13-090) (Metasploit)
MS13-090 CardSpaceClaimCollection ActiveX Integer Underflow
MS13-090 CardSpaceClaimCollection ActiveX Integer Underflow
Immunity Canvas: IE_CARDSPACECLAIMCOLLECTION
MS13-090 CardSpaceClaimCollection ActiveX Integer Underflow