Executive brief
Microsoft Windows contains a vulnerability in a component used for signing into web services. An attacker could exploit this by tricking a user into visiting a malicious website using Internet Explorer. If successful, the attacker could take full control of the user's computer, potentially leading to data theft or the installation of malware.
Technical details
An out-of-bounds write vulnerability exists in the InformationCardSigninHelper Class ActiveX control (icardie.dll) within multiple versions of Microsoft Windows. The flaw is triggered when Internet Explorer processes a specially crafted webpage, allowing a remote attacker to execute arbitrary code or cause a denial of service. This is a client-side vulnerability requiring user interaction (visiting a malicious URL). The vulnerability was notably exploited in the wild in 2013 via watering hole attacks. Microsoft released a patch (MS13-090) to address this issue, though many affected operating systems are now end-of-life.
Affected products
- Microsoft Windows XP SP2/SP3, Server 2003 SP2, Vista SP2, Server 2008 SP2/R2 SP1, 7 SP1, 8, 8.1, Server 2012/R2, RT/8.1
Timeline
- 2013-11-11: exploited: Exploited in the wild in November 2013 via watering hole attacks.
- 2013-11-12: patched: Microsoft released security bulletin MS13-090.
- 2025-10-06: kev added: Added to CISA Known Exploited Vulnerabilities catalog.