LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2013-3918: Microsoft Windows Out-of-Bounds Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 6, 2025
CVSS 8.8 · High⚠ Actively exploited (CISA KEV)
8.8
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 27, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2013-3918 to its Known Exploited Vulnerabilities catalog on Oct 6, 2025, with a federal patch deadline of Oct 27, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted web page that is accessed by Internet Explorer, as exploited in the wild in November 2013, aka "InformationCardSigninHelper Vulnerability."

CVE-2013-3918 is an out-of-bounds write vulnerability in Microsoft Windows that affects the InformationCardSigninHelper Class ActiveX control in icardie.dll. An attacker can trigger it by luring a user to view a specially crafted webpage, which may allow remote code execution with the same rights as the logged-on user. This matters because successful exploitation can give an attacker control over the affected system under the user's privileges, and the product may already be end-of-life or end-of-service, increasing long-term risk if it remains in use.

Defenders should treat this as a browser-reachable ActiveX issue on Windows endpoints and confirm all version, patch, and configuration details against the vendor advisory before acting.

How it works

The flaw is an out-of-bounds write inside the InformationCardSigninHelper Class ActiveX control (icardie.dll). When a user visits a malicious webpage that instantiates or interacts with this control, the control can write data outside the intended memory bounds. That memory corruption can be leveraged for remote code execution in the context of the current user.

No further exploit mechanics, specific memory layouts, or payload details are provided in the available facts. Attackers typically rely on social engineering or compromised sites to deliver the crafted page; once the control processes the malicious input, code runs with the privileges of the user who opened the page. Confirm exact exploitation conditions and any required user interaction against the vendor advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that expose the InformationCardSigninHelper Class ActiveX control via icardie.dll. This control is typically present on Windows clients that support older ActiveX-based identity or information-card features and can be reached through Internet Explorer or other browsers that still allow ActiveX.

Because exact affected builds are not listed here, treat any Windows system still loading this control as potentially vulnerable until verified against the vendor advisory.

How to remediate

Apply the vendor-supplied update or mitigation instructions for CVE-2013-3918 as the primary remediation. Follow Microsoft guidance exactly; if the product is end-of-life or end-of-service and no mitigations are available, discontinue use of the affected component or the product itself, consistent with CISA direction.

Re-image or rebuild systems that cannot be patched if they are no longer supported.

If you can't patch immediately

Until the vendor update can be applied or the product can be retired, reduce exposure with compensating controls focused on the ActiveX attack surface.

These measures lower risk but do not eliminate it; plan for full remediation or product discontinuation.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to system compromise and subsequent data breaches. If you suspect exploitation, isolate the host, preserve forensic evidence, and investigate for lateral movement or data access under the compromised user context. Known ransomware use of this CVE is not documented in the available facts.

You can run a free exposure scan of your email address against known breach data sets to determine whether credentials or personal information associated with your accounts have already appeared in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-787
CVSS base score8.8 (High)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
PublishedNov 12, 2013
Added to CISA KEVOct 6, 2025
Federal patch deadlineOct 27, 2025
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities