CVE-2013-3918CISA KEVEPSS p99.4%

CVE-2013-3918Microsoft Windows Out-of-Bounds Write Vulnerability

Microsoft / Windows

Description

Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a specially crafted webpage. When a user views the webpage, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Scoring

EPSS73.87% probability of exploitation · percentile 99.4% · 2026-06-18T12:00:27Z

CISA KEV entry

Added to KEV: 2025-10-06

(incoming)1

TypeTargetConfidenceTier
KEVEntryMicrosoft Windows Out-of-Bounds Write Vulnerabilitykev-cve-2013-39180%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Microsoft Internet Explorer Remote Code Execution Vulnerability
CVE
Microsoft Internet Explorer Resource Management Errors Vulnerability
CVE
Microsoft Internet Explorer Memory Corruption Vulnerability
CVE
Microsoft Internet Explorer Use-After-Free Vulnerability
CVE
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
CVE
Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.