CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2013-3918

Known Exploited (CISA KEV)HIGH
8.8
CVSS Severity Score
EPSS Score89.4210%
EPSS Percentile89.99th
Published2013年11月12日
Last Modified2026年4月22日

Vulnerability Description

The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted web page that is accessed by Internet Explorer, as exploited in the wild in November 2013, aka "InformationCardSigninHelper Vulnerability."

Affected Platforms (CPE)

💻
Microsoft

Windows 7

All versions
💻
Microsoft

Windows 8

All versions
💻
Microsoft

Windows 8.1

All versions
💻
Microsoft

Windows Rt

All versions
💻
Microsoft

Windows Rt 8.1

All versions
💻
Microsoft

Windows Server 2003

All versions
💻
Microsoft

Windows Server 2008

= r2
💻
Microsoft

Windows Server 2008

= r2
💻
Microsoft

Windows Server 2008

= sp2
💻
Microsoft

Windows Server 2012

All versions
💻
Microsoft

Windows Server 2012

= r2
💻
Microsoft

Windows Vista

All versions
💻
Microsoft

Windows Xp

All versions
💻
Microsoft

Windows Xp

All versions

References & Advisories

相關漏洞威脅