PT-2013-2085 · Microsoft · Sharepoint Server 2013+5

Published

2013-09-11

·

Updated

2018-10-12

·

CVE-2013-0081

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Portal Server 2003 SP3 Microsoft SharePoint Server 2007 SP3 Microsoft SharePoint Server 2010 SP1 Microsoft SharePoint Server 2010 SP2 Microsoft SharePoint Server 2013
Description A denial of service issue exists due to improper processing of unassigned workflows, allowing remote attackers to cause a denial of service via a crafted URL. This can lead to the W3WP process hanging, making the SharePoint site and other sites under the same process unavailable until the process is restarted.
Recommendations For Microsoft SharePoint Portal Server 2003 SP3, update to a version that properly processes unassigned workflows. For Microsoft SharePoint Server 2007 SP3, update to a version that properly processes unassigned workflows. For Microsoft SharePoint Server 2010 SP1, update to a version that properly processes unassigned workflows. For Microsoft SharePoint Server 2010 SP2, update to a version that properly processes unassigned workflows. For Microsoft SharePoint Server 2013, update to a version that properly processes unassigned workflows. As a temporary workaround, consider restricting access to crafted URLs that could exploit the denial of service vulnerability until a patch is available.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-0081

Affected Products

Sharepoint Portal Server 2003
Sharepoint Server 2007
Sharepoint Server 2010
Sharepoint Server 2013
Sharepoint Foundation
Sharepoint Server