CVE-2013-3940

Description

Integer overflow in the Graphics Device Interface (GDI) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image in a Windows Write (.wri) document, which is not properly handled in WordPad, aka Graphics Device Interface Integer Overflow Vulnerability.

Risk Information

Base Score
7.8
MODERATE
Vector
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
71.777

Associated Vulnerability

VulnerabilityOS Platform
ms13-089: vulnerability in windows graphics device interface could allow remote code execution: november 12, 2013 for Windows XP (KB2876331)Windows
ms13-089: vulnerability in windows graphics device interface could allow remote code execution: november 12, 2013 for Windows Server 2003 (KB2876331)Windows
ms13-089: vulnerability in windows graphics device interface could allow remote code execution: november 12, 2013 for Windows Vista (KB2876331)Windows
ms13-089: vulnerability in windows graphics device interface could allow remote code execution: november 12, 2013 for Windows Server 2008 (KB2876331)Windows
ms13-089: vulnerability in windows graphics device interface could allow remote code execution: november 12, 2013 for Windows 7 (KB2876331)Windows
ms13-089: vulnerability in windows graphics device interface could allow remote code execution: november 12, 2013 for Windows XP x64 Edition (KB2876331)Windows
ms13-089: vulnerability in windows graphics device interface could allow remote code execution: november 12, 2013 for Windows Server 2003 x64 Edition (KB2876331)Windows
ms13-089: vulnerability in windows graphics device interface could allow remote code execution: november 12, 2013 for Windows Vista for x64-based Systems (KB2876331)Windows
ms13-089: vulnerability in windows graphics device interface could allow remote code execution: november 12, 2013 for Windows Server 2008 x64 Edition (KB2876331)Windows
ms13-089: vulnerability in windows graphics device interface could allow remote code execution: november 12, 2013 for Windows 7 for x64-based Systems (KB2876331)Windows
ms13-089: vulnerability in windows graphics device interface could allow remote code execution: november 12, 2013 for Windows Server 2008 R2 x64 Edition (KB2876331)Windows
ms13-089: vulnerability in windows graphics device interface could allow remote code execution: november 12, 2013 for Windows 8 (KB2876331)Windows
ms13-089: vulnerability in windows graphics device interface could allow remote code execution: november 12, 2013 for Windows 8 for x64-based Systems (KB2876331)Windows
ms13-089: vulnerability in windows graphics device interface could allow remote code execution: november 12, 2013 for Windows Server 2012 (KB2876331)Windows
ms13-089: vulnerability in windows graphics device interface could allow remote code execution: november 12, 2013 for Windows 8.1 (KB2876331)Windows
ms13-089: vulnerability in windows graphics device interface could allow remote code execution: november 12, 2013 for Windows 8.1 for x64-based Systems (KB2876331)Windows
ms13-089: vulnerability in windows graphics device interface could allow remote code execution: november 12, 2013 for Windows Server 2012 R2 (KB2876331)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-14672Security Update for Windows Server 2003 (KB2876331)
PATCH-14673Security Update for Windows Vista (KB2876331)
PATCH-14674Security Update for Windows Server 2008 (KB2876331)
PATCH-14675Security Update for Windows 7 (KB2876331)
PATCH-14676Security Update for Windows XP x64 Edition (KB2876331)
PATCH-14677Security Update for Windows Server 2003 x64 Edition (KB2876331)
PATCH-14678Security Update for Windows Vista for x64-based Systems (KB2876331)
PATCH-14679Security Update for Windows Server 2008 x64 Edition (KB2876331)
PATCH-14680Security Update for Windows 7 for x64-based Systems (KB2876331)
PATCH-14681Security Update for Windows Server 2008 R2 x64 Edition (KB2876331)
PATCH-14682Security Update for Windows 8 (KB2876331)
PATCH-14683Security Update for Windows 8 for x64-based Systems (KB2876331)
PATCH-14684Security Update for Windows Server 2012 (KB2876331)
PATCH-14685Security Update for Windows 8.1 (KB2876331)
PATCH-14686Security Update for Windows 8.1 for x64-based Systems (KB2876331)
PATCH-14687Security Update for Windows Server 2012 R2 (KB2876331)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234