PT-2013-5354 · Microsoft · Internet Explorer+4

Publicado

2013-12-10

·

Atualizado

2018-10-12

·

CVE-2013-5057

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Office 2007 SP3 Microsoft Office 2010 SP1 Microsoft Office 2010 SP2
Description A security issue exists due to the lack of Address Space Layout Randomization (ASLR) protection, making it easier for attackers to execute arbitrary code. This is achieved via a crafted COM component on a visited web site with Internet Explorer. The issue has been exploited in the wild. ASLR is a security feature that randomizes the location of executable code in memory to prevent attackers from predicting where their malicious code will be loaded. Without ASLR, attackers can more easily predict where their code will be loaded, making it easier to exploit vulnerabilities.
Recommendations For Microsoft Office 2007 SP3, update to a version that implements the ASLR protection mechanism. For Microsoft Office 2010 SP1, update to a version that implements the ASLR protection mechanism. For Microsoft Office 2010 SP2, update to a version that implements the ASLR protection mechanism.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-5057

Produtos afetados

Internet Explorer
Office 2007 Sp3
Office 2010 Sp1
Office 2010 Sp2
Office