RaqibCTI
CVE

CVE-2013-3918

P2
Microsoft Windows Out-of-Bounds Write Vulnerability
Microsoft · Windows
Date added (CISA)
2025-10-06
Remediation due
2025-10-27
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a specially crafted webpage. When a user views the webpage, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Source: NVD ↗ · CISA KEV Catalog ↗