CVE-2013-3906 is a memory corruption vulnerability in Microsoft GDI+ caused by improper handling of specially crafted TIFF images. Affected products include Windows Vista SP2, Windows Server 2008 SP2, specified Office 2003–2010 releases and companion viewers, Office Compatibility Pack SP3, and specified Lync 2010 and 2013 releases. Vulnerable Office or Lync installations can expose the flaw even when the underlying operating system is otherwise unaffected. Processing malicious TIFF content, including images embedded in Word documents, permits arbitrary code execution with the current user's privileges. Exploitation was observed in October and November 2013.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (mswin_tiff_overflow.rb) that exploits CVE-2013-3906, a vulnerability in Microsoft's handling of TIFF images embedded in Office documents. The exploit targets Windows XP SP3 systems with Office Standard 2010 (32-bit). The module generates a malicious DOCX file (default name: msf.docx) containing a specially crafted TIFF image that triggers an integer overflow, leading to heap corruption and arbitrary code execution when the document is opened. The payload is customizable and leverages Metasploit's shellcode capabilities. The module is operational and suitable for use in penetration testing scenarios where the target environment matches the specified configuration. The code is written in Ruby and leverages Metasploit's file format and ROP (Return-Oriented Programming) libraries. No network endpoints are targeted; exploitation occurs via user interaction with the malicious file.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in Microsoft GDI+ triggered by a crafted TIFF image, including images embedded in Word documents. It affects the listed Windows, Office, and Lync versions and was exploited in the wild in October and November 2013. The record references an Exploit-DB exploit and Microsoft security bulletin MS13-096.
A Microsoft Office exploit used in malicious lure documents by ModifiedElephant to drop and execute malware during spearphishing campaigns.
A memory corruption vulnerability in Microsoft graphics handling allows arbitrary code execution when affected software processes specially crafted TIFF content. Attack vectors include malicious websites, Office documents, email opened or previewed with Word as the reader, and shared Lync content. Code executes with the current user's privileges, potentially allowing complete system compromise when that user has administrative rights. The bulletin reports targeted attacks against Office and specifically identifies Office 2007 on Windows XP as under active attack. Severity is Critical for affected Windows and Office products and Important for affected Lync clients. MS13-096 provides patches correcting TIFF handling. Mitigations include disabling the TIFF codec where supported, disabling Lync data collaboration, configuring EMET, and using accounts with reduced privileges. Office 2010 and PowerPoint 2010 Viewer vulnerability depends on the underlying Windows version.
A vulnerability exploited by Sandworm Team through crafted TIFF images in Microsoft Word for client execution. The content documents exploitation but provides no patch or mitigation details.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.