CVE-2013-3918

9.5 CISA KEV

Microsoft · Windows

A critical out-of-bounds write vulnerability in the InformationCardSigninHelper ActiveX control in icardie.dll allows remote code execution via a specially crafted webpage in Internet Explorer.

Executive summary

This critical remote code execution vulnerability in Microsoft Windows, which is actively listed in the CISA Known Exploited Vulnerabilities catalog, poses an immediate risk of system compromise.

Vulnerability

The InformationCardSigninHelper Class ActiveX control in icardie.dll contains an out-of-bounds write vulnerability that allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service when a victim visits a malicious webpage using Internet Explorer.

Business impact

The vulnerability carries a CVSS score of 9.5, indicating a critical severity level. Successful exploitation allows for full system compromise, enabling attackers to execute code with the privileges of the logged-in user. This flaw has been historically linked to sophisticated APT groups, and its presence in the CISA KEV catalog underscores the high risk of data theft, unauthorized access, and significant operational disruption.

Remediation

Immediate Action: Apply the cumulative security update KB2900986 to implement the necessary ActiveX kill bits and mitigate the vulnerability.

Proactive Monitoring: Review web proxy and firewall logs for traffic directed toward suspicious external domains that may be hosting malicious, crafted webpages designed to trigger ActiveX exploits.

Compensating Controls: If patching is not immediately feasible, disable the InformationCardSigninHelper ActiveX control via Group Policy or registry settings to prevent instantiation within Internet Explorer.

Exploitation status

Public Exploit Available: Yes, a Metasploit module and ExploitDB entry exist.

Analyst recommendation

Given the critical CVSS severity and the documented history of active exploitation by sophisticated threat actors, immediate remediation is mandatory. Organizations must prioritize the deployment of KB2900986 to ensure the vulnerable ActiveX control is effectively neutralized. Failure to address this vulnerability increases the risk of remote code execution and persistent unauthorized access to the environment.

More Microsoft CVEs

Sources