Microsoft Updates November 2013
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2013-3918 | Out-of-Bounds Write RCE in Microsoft Windows InformationCardSigninHelper ActiveX CVE-2013-3918 is an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control (icardie.dll) that ships with Internet Explorer on Microsoft Windows. An attacker triggers it by luring a user to a specially crafted web page; when the page invokes the affected ActiveX control, memory is written outside its allocated bounds and remote code execution can result. A successful attacker gains the same privileges as the currently logged-on user, so code executed under an administrator account would run with full administrative rights. Any Windows system with the vulnerable control present is affected — CISA lists 'Microsoft Windows' broadly without specific version ranges, and notes impacted releases may be end-of-life or end-of-service. The flaw has been exploited in the wild since its November 2013 disclosure, was fixed in an out-of-band update at the time, and CISA added it to the KEV catalog on 2025-10-06 with a very high EPSS of 73.9% (probability of exploitation within 30 days). Do: Apply Microsoft's vendor fix for CVE-2013-3918 — the November 2013 out-of-band Internet Explorer cumulative security update (MS13-090) — or any later cumulative IE update on systems still in service; on systems that cannot be patched, set the killbit/disable the InformationCardSigninHelper ActiveX control or discontinue use of the EoL/EoS Windows releases per CISA guidance. Federal agencies must complete the required action within the BOD 22-01 deadline following the 2025-10-06 KEV addition. Verify that icardie.dll is no longer loadable in Internet Explorer (or IE mode in Edge) and that legacy IE usage is minimized across the estate. | — | 74% | KEV |
| mass≈1 billion Windows endpoints at disclosure (effectively the global Windows estate, since the affected IE ActiveX control shipped by default); today mostly… |
Full article458 words · extracted from securelist.com · click to collapse
Microsoft’s November 2013 Patch Tuesday delivers a set of three critical Bulletins and five Bulletins rated “important”. This month’s MS13-088 patches eight critical vulnerabilities and two important vulnerabilities in Internet Explorer. Overall, Microsoft is addressing 19 issues in Internet Explorer, Office and Windows itself.
The star of the show is MS13-090 which addresses CVE-2013-3918, an ActiveX vulnerability being attacked through Internet Explorer, revealed on the 8th by the guys at FireEye to be abused by a long running APT operation they call “DeputyDog”. As a part of this operation, the group strategically popped yet another carefully selected web site, then redirected those visitors to their 0day attack. Simply labelling it “just another watering hole” may not fully describe the amount of planning and preparation that goes into selecting the web site property to compromise, and then burn the 0day on attack activity. The identity of the compromised web property in this case has not been publicly disclosed to date. The timing of this 0day delivery could quite possibly reveal the operational maturity of this group as well. On another note, I don’t know if I missed something, but in my decade or so of reviewing shellcoding techniques, I don’t think that I have ever seen “CreateRemoteThread” used to deliver a payload in a significant exploit.
At the same time, another whopping eight flaws are being fixed in Internet Explorer with MS013-088. No doubt these should be patched by organizations immediately, as the memory corruption issues invite exploit development attention. A few of the eight CVE include issues with “information disclosure”, which enable exploit developers to advance their exploit code further into process space and are serious issues.
Surprisingly, Microsoft is patching code in their WordPerfect converter “wpft532.cnv” for stack overflow issue CVE-2013-1324. This vulnerability enables spearphish attacks across all versions of their OS, but on 64bit platforms, the component may not be present. I didn’t expect to write about stack BoF in their code at the end of 2013, but hey, it’s tricky stuff.
More about this month’s patches can be found at the Microsoft site.
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/microsoft-updates-november-2013-burning-the-0day/57202/