CVE-2013-3918Active Exploitation(microsoft / windows_7)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch microsoft windows_7 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted web page that is accessed by Internet Explorer, as exploited in the wild in November 2013, aka "InformationCardSigninHelper Vulnerability."

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-10-27. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_7
  • windows_8
  • windows_8.1
  • windows_rt

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
windows_7windows_8windows_8.1windows_rtwindows_rt_8.1windows_server_2003windows_server_2008windows_server_2012windows_vistawindows_xp

3 versions affected across 10 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-01: 2Active Exploitation · 2026-05-01: 2Patch / Workaround · 2026-05-01: 1Technical Details · 2026-05-01: 105-01
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2013-3918: CVE-2013-3918: Windows ActiveX (icardie.dll) out-of-bounds write allows RCE via crafted webpage; CISA added to KEV—remediate or discontinue EoL/EoS.

    Post summary

    CISA has listed CVE-2013-3918 in the KEV, confirming it is being exploited in the wild to achieve remote code execution via crafted web pages, and the advisory recommends remediation or discontinuation.

    1001045
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2013-3918-windows #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided link suggests that CVE‑2013‑3918 is actively exploited on Windows, but the message lacks detailed evidence or additional context.

    0000035
    152 followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_7---
OSmicrosoftwindows_8---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2003---
OSmicrosoftwindows_server_2008r2-itanium
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2008sp2--
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_vista---
OSmicrosoftwindows_xp--x64
OSmicrosoftwindows_xp---

Explore more