Executive Summary

Summary
Title Vulnerabilities in FAST Search Server 2010 for SharePoint Parsing Could Allow Remote Code Execution (2784242)
Informations
Name MS13-013 First vendor Publication 2013-02-12
Vendor Microsoft Last vendor Modification 2013-02-12
Severity (Vendor) Important Revision 1.0

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:N/I:N/A:P)
Cvss Base Score 2.1 Attack Range Local
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 3.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Revision Note: V1.0 (February 12, 2013): Bulletin published.

Summary: This security update resolves publicly disclosed vulnerabilities in Microsoft FAST Search Server 2010 for SharePoint. The vulnerabilities could allow remote code execution in the security context of a user account with a restricted token. FAST Search Server for SharePoint is only affected by this issue when Advanced Filter Pack is enabled. By default, Advanced Filter Pack is disabled.

Original Source

Url : http://technet.microsoft.com/en-us/security/bulletin/ms13-013

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:15911
 
Oval ID: oval:org.mitre.oval:def:15911
Title: Oracle Outside In Contains Multiple Exploitable Vulnerabilities-II MS12-080
Description: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7.0 allows context-dependent attackers to affect availability, related to Outside In HTML Export SDK.
Family: windows Class: vulnerability
Reference(s): CVE-2012-3217
Version: 3
Platform(s): Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Product(s): Microsoft Exchange Server 2007
Microsoft Exchange Server 2010
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16080
 
Oval ID: oval:org.mitre.oval:def:16080
Title: Oracle Outside In Contains Multiple Exploitable Vulnerability - CVE-2012-3217 (MS13-013)
Description: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7.0 allows context-dependent attackers to affect availability, related to Outside In HTML Export SDK.
Family: windows Class: vulnerability
Reference(s): CVE-2012-3217
Version: 3
Platform(s): Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Product(s): Microsoft FAST Search Server 2010 for SharePoint
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16178
 
Oval ID: oval:org.mitre.oval:def:16178
Title: Oracle Outside In Contains Multiple Exploitable Vulnerabilities-I MS12-080
Description: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7.0 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.
Family: windows Class: vulnerability
Reference(s): CVE-2012-3214
Version: 3
Platform(s): Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Product(s): Microsoft Exchange Server 2007
Microsoft Exchange Server 2010
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16500
 
Oval ID: oval:org.mitre.oval:def:16500
Title: Oracle Outside In Contains Multiple Exploitable Vulnerability - CVE-2012-3214 (MS13-013)
Description: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7.0 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.
Family: windows Class: vulnerability
Reference(s): CVE-2012-3214
Version: 3
Platform(s): Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Product(s): Microsoft FAST Search Server 2010 for SharePoint
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1

OpenVAS Exploits

Date Description
2012-12-12 Name : MS Exchange Server Remote Code Execution Vulnerabilities (2784126)
File : nvt/secpod_ms12-080.nasl

Information Assurance Vulnerability Management (IAVM)

Date Description
2013-02-14 IAVM : 2013-A-0044 - Multiple Vulnerabilities in FAST Search Server 2010 for Microsoft SharePoint
Severity : Category II - VMSKEY : V0036831

Nessus® Vulnerability Scanner

Date Description
2013-02-12 Name : The remote Windows host is affected by multiple code execution vulnerabilities.
File : smb_nt_ms13-013.nasl - Type : ACT_GATHER_INFO
2012-12-11 Name : The remote mail server has multiple vulnerabilities.
File : smb_nt_ms12-080.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
Date Informations
2014-02-17 11:47:33
  • Multiple Updates
2013-11-11 12:41:32
  • Multiple Updates
2013-02-14 13:26:11
  • Multiple Updates
2013-02-12 21:22:10
  • Multiple Updates
2013-02-12 21:18:29
  • First insertion