← Back to browse · API

CVE-2013-3918

Severity
HIGH
CVSS
8.8
EPSS
0.73872
Risk score
86.06
CISA KEV
Yes
PoC
No
Published
2025-10-06
Modified
2025-10-06
First seen
2026-08-07
Aliases
EUVD-2013-3850, GHSA-7627-VGQ8-RCJV
Products
Microsoft:Windows, n/a:n/a n/a
Sources
euvd EUVD-2013-3850
cisa.gov CVE-2013-3918

Description

Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a specially crafted webpage. When a user views the webpage, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

References