CVE-2013-3940
Last modified
CVE-2013-3940 is a vulnerability of currently unknown severity. Integer overflow in the Graphics Device Interface (GDI) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image in a Windows Write (.wri) document, which is not properly handled in WordPad, aka "Graphics Device Interface Integer Overflow Vulnerability.". EPSS estimates a 34.45% chance of exploitation in the next 30 days.
Description
Integer overflow in the Graphics Device Interface (GDI) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image in a Windows Write (.wri) document, which is not properly handled in WordPad, aka "Graphics Device Interface Integer Overflow Vulnerability."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Windows 7 | All versions | Sp1 |
| Microsoft | Windows 8 | All versions | — |
| Microsoft | Windows 8.1 | All versions | — |
| Microsoft | Windows Rt | All versions | — |
| Microsoft | Windows Rt 8.1 | All versions | — |
| Microsoft | Windows Server 2003 | All versions | Sp2 |
| Microsoft | Windows Server 2008 | All versions | Sp2 |
| Microsoft | Windows Server 2008 | r2 | Sp1 |
| Microsoft | Windows Server 2012 | All versions | — |
| Microsoft | Windows Server 2012 | r2 | — |
| Microsoft | Windows Vista | All versions | Sp2 |
| Microsoft | Windows Xp | All versions | Sp2 |
References
- http://www.us-cert.gov/ncas/alerts/TA13-317AThird Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-089Patch, Vendor Advisory
- http://www.us-cert.gov/ncas/alerts/TA13-317AThird Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-089Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-3940?
How severe is CVE-2013-3940?
How do I fix CVE-2013-3940?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-3934Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.30…
- CVE-2013-3935Cross-site request forgery (CSRF) vulnerability in Opsview b…8.8
- CVE-2013-3936Multiple cross-site scripting (XSS) vulnerabilities in Opsvi…6.1
- CVE-2013-3937Heap-based buffer overflow in xnview.exe in XnView before 2.…7.8
- CVE-2013-3938Integer overflow in xnview.exe in XnView 2.13 allows remote …
- CVE-2013-3939xnview.exe in XnView before 2.13 does not properly handle RL…7.8
- CVE-2013-3941Xjp2.dll in XnView before 2.13 allows remote attackers to ex…9.8
- CVE-2013-3942Potplayer prior to 1.5.39659: DLL Loading Arbitrary Code Exe…7.8
- CVE-2013-3943Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN)…
- CVE-2013-3944Stack-based buffer overflow in the MrSID plugin (MrSID.dll) …7.8
- CVE-2013-3945The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allow…7.8
- CVE-2013-3946Heap-based buffer overflow in the MrSID plugin (MrSID.dll) b…7.8
Are you affected by CVE-2013-3940?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
