CVE-2013-3918 describes an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control (icardie.dll) affecting numerous Microsoft Windows versions, including XP, Vista, Windows 7, 8, and Server editions. This flaw allows remote attackers to execute arbitrary code or cause a denial of service via a crafted web page accessed through Internet Explorer. With a CVSS score of 8.8 (HIGH), it presents a critical risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. The vulnerability has been actively exploited in the wild since November 2013, with exploit code available in Metasploit and significant community discussion, indicating its widespread recognition and potential for abuse.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.