PT-2013-4691 · Microsoft · Sharepoint Server 2010+9

Ben Hawkes

+2

·

Published

2013-09-11

·

Updated

2018-10-12

·

CVE-2013-3857

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Word Automation Services in SharePoint Server 2010 SP1 and SP2 Word Web App 2010 SP1 and SP2 in Office Web Apps 2010 Word 2003 SP3 Word 2007 SP3 Word 2010 SP1 and SP2 Office Compatibility Pack SP3 Word Viewer
Description The issue allows remote attackers to execute arbitrary code or cause a denial of service due to memory corruption via a crafted Office document. Remote code execution vulnerabilities exist in the way that affected Microsoft Office software parses specially crafted files, potentially allowing an attacker to take complete control of an affected system.
Recommendations For Microsoft Word Automation Services in SharePoint Server 2010 SP1 and SP2, update to a version that includes the fix for this issue. For Word Web App 2010 SP1 and SP2 in Office Web Apps 2010, update to a version that includes the fix for this issue. For Word 2003 SP3, update to a version that includes the fix for this issue. For Word 2007 SP3, update to a version that includes the fix for this issue. For Word 2010 SP1 and SP2, update to a version that includes the fix for this issue. For Office Compatibility Pack SP3, update to a version that includes the fix for this issue. For Word Viewer, update to a version that includes the fix for this issue.

Fix

RCE

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3857

Affected Products

Word Automation Services
Office Compatibility Pack
Office Web Apps 2010
Office Word
Sharepoint Server 2010
Word 2003
Word 2007
Word 2010
Word Viewer
Word Web App 2010