Junglewise Threat Intelligence

CVE-2013-3906: Microsoft Graphics Component Memory Corruption Vulnerability

CVE-2013-3906 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-02-15

Technologies: Microsoft Windows Vista, Microsoft Office 2003, Microsoft Windows Server 2008, Microsoft Graphics Component. Vendors: Microsoft.

Executive brief

A memory corruption vulnerability in the Microsoft Graphics Component (GDI+) allows for remote code execution via specially crafted TIFF images. Attackers can exploit this by embedding malicious images in documents, such as Microsoft Word files, which execute code when processed by the vulnerable component.

Affected products

  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2
  • Microsoft Office 2003 SP3
  • Microsoft Office 2007 SP3
  • Microsoft Office 2010 SP1, SP2
  • Microsoft Office Compatibility Pack SP3
  • Microsoft Lync 2010 Attendee
  • Microsoft Lync 2013 Basic 2013

Timeline

  • 2013-10: exploited: Exploited in the wild in October and November 2013.
  • 2022-02-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-02-15: disclosed

Related threats