CVE detail
CVE-2013-3906
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execute arbitrary code via a crafted TIFF image, as demonstrated by an image in a Word document, and exploited in the wild in October and November 2013.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 28.9 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
17 source links · newest first
The United States Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday announced that it has expanded its Known Exploited Vulnerabilities Catalog with nine more security flaws, including two recently addressed zero-days.
newswww.securityweek.comFeb 16, 2022, 12:52 PM- CISA added 9 new flaws to the Known Exploited Vulnerabilities Catalog, including Magento e Chrome bugsSecurity Affairs
The U.S. CISA added to the Known Exploited Vulnerabilities Catalog another 9 security flaws actively exploited in the wild. US Cybersecurity and Infrastructure Security Agency (CISA) added nine new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including two recently patched zero-day issues affecting Adobe Commerce/Magento Open Source and Google Chrome. CISA orders all Federal Civilian Executive […]
newssecurityaffairs.comFeb 16, 2022, 10:04 AM For roughly a decade, a previously unknown advanced persistent threat (APT) actor has been engaging in long-term surveillance operations against academics, activists, journalists, human rights defenders, and law professionals, SentinelOne reports.
newswww.securityweek.comFeb 11, 2022, 4:08 PM- The evolutions of APT28 attacksSecurity Affairs
Analyzing how tactics, techniques and procedures of the Russia-linked APT28 cyberespionage group evolve over the time. APT28 is a well known Russian cyber espionage group attributed, with a medium level of confidence, to Russian military intelligence agency GRU (by CrowdStrike). It is also known as Sofacy Group (by Kaspersky) or STRONTIUM (by Microsoft) and it’s used to target Aereospace, Defence, Governmente Agencies, International […]
newssecurityaffairs.comDec 5, 2019, 6:41 AM The Russian Sandworm APT group if the first suspect for the Ukrainian power outage, states experts at eiSight Partners. According to a report published by experts at eiSight Partners the cyber attack against a Ukraine power station has been managed by a Russian group called Sandworm. A few days ago experts at ESET reported the existence of a […]
newssecurityaffairs.comJan 8, 2016, 2:39 PMSummary While threat actors using the PlugX Trojan typically leverage legitimate executables to load their malicious DLLs through a technique called DLL side-loading, Unit 42 has observed a new executable in use for this purpose. Threat actors are now using this previously unseen executable, created by Samsung, to load variants of the PlugX Trojan. Using
vendorunit42.paloaltonetworks.comMay 1, 2015, 10:29 AMA multinational gang of cybercriminals infiltrated more than 100 banks across 30 countries and made off with up to one billion dollars over a period of roughly two years, Kaspersky Lab said on Saturday. Kaspersky Lab, INTERPOL, Europol and authorities from different countries joined forces to to uncover the plot, which is being called an “unprecedented cyber robbery.”
newswww.securityweek.comFeb 15, 2015, 7:16 PMSometimes “Patch Tuesday” comes and goes with little excitement or fanfare; yesterday was not one of those days. In just one day, Oracle released patches for 154 new vulnerabilities, Adobe issued updates for Flash and ColdFusion, and Microsoft released 24 patches of their own. On top of the sheer volume of patches, we learned that
vendorunit42.paloaltonetworks.comOct 15, 2014, 4:45 PMiSIGHT Partners firm uncovered a Russian hacking team dubbed Sandworm that was running a cyber espionage campaign on NATO and other Government entities. According to a new report issued by the cyber security firm iSIGHT Partners a group of Russian hackers has been exploiting a previously unknown flaw in Microsoft’s Windows operating system to spy on […]
newssecurityaffairs.comOct 14, 2014, 7:41 AMMicrosoft issued 11 security bulletins today to wrap up the final Patch Tuesday of the year.
newswww.securityweek.comDec 10, 2013, 10:41 PMOn Friday, security researchers at FireEye identified a new IE zero-day exploit hosted on a hacked U.S. website that is being used for targeted drive-by download attacks. The malware exploiting IE is injected directly into PC memory instead of being written to disk; the campaign has been dubbed Operation Ephemeral Hydra. While the U.S. website […]
newswww.csoonline.comNov 11, 2013, 4:25 PM- FireEye has identified a new IE zero-day exploitSecurity Affairs
FireEye Labs has identified a new IE zero-day exploit used for a watering hole attack in the US. As usual it is crucial to track and mitigate so dangerous threats in time to avoid serious problems. FireEye Labs has detected a new series of attacks based on the exploit of a new IE zero-day vulnerability […]
newssecurityaffairs.comNov 11, 2013, 7:47 AM - Week in review: TrueCrypt’s public security audit, new MS 0-day exploited, new bug bounty programsHelp Net Security
Here’s an overview of some of last week’s most interesting news, videos, reviews and articles: ENISA issues recommendations for securing data using cryptography ENISA, the European Union’s “cyber security” Agency, launched a report recommending that all authorities should better promote cryptographic measure to safeguard personal data. The report addresses ways to protect sensitive and/or personal data that has been acquired legitimately. US agency employees let invented woman expert into the network Once again, and more … More →
newswww.helpnetsecurity.comNov 11, 2013, 12:00 AM - Microsoft 0-Days: An Explanation and Safety TipsMalwarebytes Labs
[Update]: Microsoft has announced it will issue a patch for the newly discovered IE zero day tomorrow as part of the…
newswww.malwarebytes.comNov 10, 2013, 5:00 PM Do you still have images enabled in Outlook? If so, then right now is a great time to disable pictures since there’s a new Microsoft zero-day vulnerability. The newest exploit combines multiple techniques to bypass DEP [data execution prevention] and ASLR [address space layout randomization] protections. The graphics vulnerability exploited through Word, according to Microsoft, […]
newswww.csoonline.comNov 6, 2013, 9:20 PMMicrosoft Zero-day CVE-2013-3906 – Microsoft informed to be aware of a vulnerability in a Microsoft graphics component that is actively exploited in targeted attacks using crafted Word documents sent by email. A new zero-day vulnerability has been found a Microsoft product that could allow attackers to install a malware via infected Word documents. The Microsoft […]
newssecurityaffairs.comNov 6, 2013, 9:13 AM- New Microsoft 0-day vulnerability under attackHelp Net Security
Microsoft has released security advisory KB2896666 informing of a vulnerability (CVE-2013-3906) in the TIFF graphics format that is seeing limited attacks in the Middle East and South Asia. The vulnerability is present in Microsoft Office 2003, 2007 and 2010 and some of the older Windows Operating Systems, and the currently observed attack vector is through Microsoft Word Documents. Microsoft has provided a Fix-It that turns off TIFF rendering in the affected graphics library, which should … More →
newswww.helpnetsecurity.comNov 6, 2013, 2:26 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2009-2528CVSS 9.3 · Critical
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Off…
- CVE-2009-2503CVSS 9.3 · Critical
GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Projec…
- CVE-2013-0007CVSS 9.3 · Critical
Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka…
- CVE-2018-8432CVSS 7.8 · High
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Remote Code Execution Vulne…
- CVE-2009-3126CVSS 9.3 · Critical
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 200…
- CVE-2009-2504CVSS 9.3 · Critical
Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista…