ZeroHour

CVE-2013-3906

KEVmass

Memory Corruption RCE in Microsoft Graphics Component (Actively Exploited)

CISA: Microsoft Graphics Component Memory Corruption Vulnerability

CVSS
EPSS
85%p100
Published
KEV added
AI analysis

Microsoft's Graphics Component contains a memory corruption vulnerability that can allow remote code execution when the component processes maliciously crafted graphics content, typically delivered inside documents or other rendered content. An attacker who successfully triggers the flaw gains the ability to execute arbitrary code on the target system in the context of the current user, inheriting that user's privileges. Any Microsoft Windows system running an affected version of the Graphics Component is exposed, since the component is part of the Windows platform and is reachable through normal document and image rendering. The flaw was exploited as a zero-day in targeted attacks — notably by the Sandworm threat group against Ukrainian government and NATO-related targets, per iSight Partners reporting — and was addressed in Microsoft's December 2013 security updates. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-02-15, and EPSS currently assigns an 85% probability of exploitation within 30 days (100th percentile).

What to do: Apply the vendor's December 2013 security updates covering the Graphics Component (MS13-098) to all Windows systems, prioritizing legacy machines that may have never received the patch, and verify KEV remediation compliance if you are a federal agency. Because exploitation vectors historically involved malicious document rendering, reinforce email filtering and Office attack-surface reduction (e.g., blocking untrusted embedded graphics/objects) on any systems that remain unpatched.

Affected
Microsoft Graphics Component
Estimated exposure
mass≈1 billion+ Windows installations carried the component at the time of disclosure; residual exposure is limited to systems never patched with the December 2013… — The Graphics Component ships with the Windows platform itself, so the plausibly affected population is essentially the unpatched Windows install base — over a billion Windows devices existed when the December 2013 fix shipped.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution.

CISA Known Exploited Vulnerability
Affected
Microsoft Graphics Component
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Graphics Component
Weakness
CWE-94

In the news