Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-3906


GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execute arbitrary code via a crafted TIFF image, as demonstrated by an image in a Word document, and exploited in the wild in October and November 2013.


Published

2013-11-06T15:55:05.860

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-94
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microsoft excel_viewer - Yes
Application microsoft lync 2010 Yes
Application microsoft lync 2013 Yes
Application microsoft office 2003 Yes
Application microsoft office 2007 Yes
Application microsoft office 2010 Yes
Application microsoft office 2010 Yes
Application microsoft office_compatibility_pack - Yes
Application microsoft powerpoint_viewer 2010 Yes
Application microsoft powerpoint_viewer 2010 Yes
Application microsoft word_viewer - Yes
Operating System microsoft windows_server_2008 - Yes
Operating System microsoft windows_vista - Yes

References