Vulnerability Description
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execute arbitrary code via a crafted TIFF image, as demonstrated by an image in a Word document, and exploited in the wild in October and November 2013.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Excel Viewer | - |
| Microsoft | Lync | 2010 |
| Microsoft | Office | 2003 |
| Microsoft | Office Compatibility Pack | - |
| Microsoft | Powerpoint Viewer | 2010 |
| Microsoft | Word Viewer | - |
| Microsoft | Windows Server 2008 | - |
| Microsoft | Windows Vista | - |
Related Weaknesses (CWE)
References
- http://blogs.mcafee.com/mcafee-labs/mcafee-labs-detects-zero-day-exploit-targetiBroken LinkExploit
- http://blogs.technet.com/b/srd/archive/2013/11/05/cve-2013-3906-a-graphics-vulneBroken LinkExploit
- http://technet.microsoft.com/security/advisory/2896666PatchVendor Advisory
- http://www.exploit-db.com/exploits/30011ExploitThird Party AdvisoryVDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-09PatchVendor Advisory
- http://blogs.mcafee.com/mcafee-labs/mcafee-labs-detects-zero-day-exploit-targetiBroken LinkExploit
- http://blogs.technet.com/b/srd/archive/2013/11/05/cve-2013-3906-a-graphics-vulneBroken LinkExploit
- http://technet.microsoft.com/security/advisory/2896666PatchVendor Advisory
- http://www.exploit-db.com/exploits/30011ExploitThird Party AdvisoryVDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-09PatchVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-US Government Resource
FAQ
What is CVE-2013-3906?
CVE-2013-3906 is a vulnerability with a CVSS score of 7.8 (HIGH). GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remot...
How severe is CVE-2013-3906?
CVE-2013-3906 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-3906?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Excel Viewer, Microsoft Lync, Microsoft Office, Microsoft Office Compatibility Pack, Microsoft Powerpoint Viewer.