CVE-2013-3918

HIGH KEV

Microsoft Windows 7 - Out-of-Bounds Write

Title source: rule

Description

The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted web page that is accessed by Internet Explorer, as exploited in the wild in November 2013, aka "InformationCardSigninHelper Vulnerability."

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/29857
metasploit WORKING POC NORMAL
by Unknown, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ms13_090_cardspacesigninhelper.rb

Scores

CVSS v3 8.8
EPSS 0.8702
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CISA KEV 2025-10-06
VulnCheck KEV 2013-11-12
InTheWild.io 2019-05-14
ENISA EUVD EUVD-2013-3850
CWE
CWE-787
Status published
Products (12)
microsoft/windows_7 (2 CPE variants)
microsoft/windows_8
microsoft/windows_8.1
microsoft/windows_rt
microsoft/windows_rt_8.1
microsoft/windows_server_2003
microsoft/windows_server_2008 r2 sp1 (2 CPE variants)
microsoft/windows_server_2008 sp2
microsoft/windows_server_2012
microsoft/windows_server_2012 r2
... and 2 more
Published Nov 12, 2013
KEV Added Oct 06, 2025
Tracked Since Feb 18, 2026