Microsoft Windows Out-of-Bounds Write Vulnerability

Release Date: 06th of October 2025

Impact : HIGH / CRITICAL

TLP Rating: Clear

The Department of Communication and Digital Transformation (DCDT through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2013-3918 is an out-of-bounds write / memory-corruption vulnerability in the InformationCardSigninHelper ActiveX control (icardie.dll) that Internet Explorer can load, allowing remote code execution when a user opens a specially crafted web page.

 

References

  1. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  2. https://www.cve.org/CVERecord?id=CVE-2013-3918
  3. https://learn.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-090