CVE-2013-3906

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Nov 6, 2013
Updated: Dec 19, 2024
CWE ID 94

Summary

CVE-2013-3906 is a vulnerability affecting multiple Microsoft products, including Windows Vista SP2 and Server 2008 SP2, various Office applications, and Lync. Hackers can exploit this GDI+ issue by sending specially crafted TIFF images, often through a Word document, to execute arbitrary code remotely. This vulnerability was exploited in the wild in October and November 2013.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Vista
  • Microsoft Office
  • Skype for Business
  • Microsoft Windows Server 2008

Affected Vendors

  • Microsoft