CVE-2013-3906
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Nov 6, 2013
Updated: Dec 19, 2024
CWE ID 94
Summary
CVE-2013-3906 is a vulnerability affecting multiple Microsoft products, including Windows Vista SP2 and Server 2008 SP2, various Office applications, and Lync. Hackers can exploit this GDI+ issue by sending specially crafted TIFF images, often through a Word document, to execute arbitrary code remotely. This vulnerability was exploited in the wild in October and November 2013.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Vista
- Microsoft Office
- Skype for Business
- Microsoft Windows Server 2008
Affected Vendors
- Microsoft