CVE-2013-3918
9.5 CISA KEVMicrosoft · Windows
A critical out-of-bounds write vulnerability in the InformationCardSigninHelper ActiveX control in icardie.dll allows remote code execution via a specially crafted webpage in Internet Explorer.
Executive summary
This critical remote code execution vulnerability in Microsoft Windows, which is actively listed in the CISA Known Exploited Vulnerabilities catalog, poses an immediate risk of system compromise.
Vulnerability
The InformationCardSigninHelper Class ActiveX control in icardie.dll contains an out-of-bounds write vulnerability that allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service when a victim visits a malicious webpage using Internet Explorer.
Business impact
The vulnerability carries a CVSS score of 9.5, indicating a critical severity level. Successful exploitation allows for full system compromise, enabling attackers to execute code with the privileges of the logged-in user. This flaw has been historically linked to sophisticated APT groups, and its presence in the CISA KEV catalog underscores the high risk of data theft, unauthorized access, and significant operational disruption.
Remediation
Immediate Action: Apply the cumulative security update KB2900986 to implement the necessary ActiveX kill bits and mitigate the vulnerability.
Proactive Monitoring: Review web proxy and firewall logs for traffic directed toward suspicious external domains that may be hosting malicious, crafted webpages designed to trigger ActiveX exploits.
Compensating Controls: If patching is not immediately feasible, disable the InformationCardSigninHelper ActiveX control via Group Policy or registry settings to prevent instantiation within Internet Explorer.
Exploitation status
Public Exploit Available: Yes, a Metasploit module and ExploitDB entry exist.
Analyst recommendation
Given the critical CVSS severity and the documented history of active exploitation by sophisticated threat actors, immediate remediation is mandatory. Organizations must prioritize the deployment of KB2900986 to ensure the vulnerable ActiveX control is effectively neutralized. Failure to address this vulnerability increases the risk of remote code execution and persistent unauthorized access to the environment.
More Microsoft CVEs
Sources
- TA13-317A Third-party advisory
- darkreading.com
- MS13-090 Vendor advisory
- fireeye.com
- oval:org.mitre.oval:def:19089 Vulnerability database entry
- isc.sans.edu
- blogs.technet.com