Microsoft Office Remote Code Execution Vulnerabilities
Last Update Date:
11 Sep 2013 14:47
Release Date:
11 Sep 2013
3970
Views
RISK: Medium Risk
TYPE: Clients - Productivity Products
- XML External Entities Resolution Vulnerability
An information disclosure vulnerability exists in the way that Microsoft Word parses specially crafted XML files containing external entities. - Multiple Memory Corruption Vulnerabilities in Microsoft Word
Remote code execution vulnerabilities exist in the way that affected Microsoft Office software parses specially crafted files. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Impact
- Remote Code Execution
System / Technologies affected
- Microsoft Office 2003
- Microsoft Office 2007
- Microsoft Office 2010
- Microsoft Office Compatibility Pack
- Microsoft Word Viewer
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
http://technet.microsoft.com/en-us/security/bulletin/MS13-072
Vulnerability Identifier
- CVE-2013-3160
- CVE-2013-3847
- CVE-2013-3848
- CVE-2013-3849
- CVE-2013-3850
- CVE-2013-3851
- CVE-2013-3852
- CVE-2013-3853
- CVE-2013-3854
- CVE-2013-3855
- CVE-2013-3856
- CVE-2013-3857
- CVE-2013-3858
Source
Related Link
Share with