Executive Summary
Summary | |
---|---|
Title | Vulnerability in Microsoft Office Could Allow Remote Code Execution (2839571) |
Informations | |||
---|---|---|---|
Name | MS13-051 | First vendor Publication | 2013-06-11 |
Vendor | Microsoft | Last vendor Modification | 2013-06-11 |
Severity (Vendor) | Important | Revision | 1.0 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Revision Note: V1.0 (June 11, 2013): Bulletin published. |
Original Source
Url : http://technet.microsoft.com/en-us/security/bulletin/ms13-051 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:16713 | |||
Oval ID: | oval:org.mitre.oval:def:16713 | ||
Title: | Vulnerability in Microsoft Office could allow remote code execution - MS13-051 (Mac OS X) | ||
Description: | Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability." | ||
Family: | macos | Class: | vulnerability |
Reference(s): | CVE-2013-1331 | Version: | 3 |
Platform(s): | Apple Mac OS X Apple Mac OS X Server | Product(s): | Microsoft Office 2011 for Mac |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:16732 | |||
Oval ID: | oval:org.mitre.oval:def:16732 | ||
Title: | Vulnerability in Microsoft Office could allow remote code execution - MS13-051 | ||
Description: | Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2013-1331 | Version: | 3 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows 7 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows Vista Microsoft Windows XP | Product(s): | Microsoft Office 2003 |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 2 |
SAINT Exploits
Description | Link |
---|---|
Microsoft Office PNG File Handling Buffer Overflow | More info here |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2013-06-13 | IAVM : 2013-A-0121 - Microsoft Office Remote Code Execution Vulnerability Severity : Category I - VMSKEY : V0039073 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Multiple Products malformed PNG detected tEXt overflow attempt RuleID : 6700 - Revision : 20 - Type : FILE-IMAGE |
2019-09-24 | Microsoft Office PNG tEXt chunk buffer overflow attempt RuleID : 51206 - Revision : 1 - Type : FILE-IMAGE |
2019-09-24 | Microsoft Office PNG tEXt chunk buffer overflow attempt RuleID : 51205 - Revision : 1 - Type : FILE-IMAGE |
2019-09-24 | Microsoft Office PNG tEXt chunk buffer overflow attempt RuleID : 51204 - Revision : 1 - Type : FILE-IMAGE |
2019-09-24 | Microsoft Office PNG tEXt chunk buffer overflow attempt RuleID : 51203 - Revision : 1 - Type : FILE-IMAGE |
2014-03-27 | Microsoft Multiple Products potentially malicious PNG detected - large or inv... RuleID : 29945 - Revision : 4 - Type : FILE-IMAGE |
2014-03-27 | Microsoft Office PNG parsing stack buffer overflow attempt RuleID : 29944 - Revision : 4 - Type : FILE-IMAGE |
2014-01-10 | Microsoft Multiple Products malformed PNG detected tEXt overflow attempt RuleID : 26865 - Revision : 4 - Type : FILE-IMAGE |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-06-11 | Name : An application installed on the remote Mac OS X host is affected by a remote ... File : macosx_ms13-051.nasl - Type : ACT_GATHER_INFO |
2013-06-11 | Name : The remote Office install has a buffer overflow vulnerability. File : smb_nt_ms13-051.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-03-27 21:20:56 |
|
2014-02-17 11:47:42 |
|
2014-01-19 21:30:57 |
|
2013-11-11 12:41:34 |
|
2013-11-04 21:33:45 |
|
2013-06-12 17:21:29 |
|
2013-06-12 13:21:33 |
|
2013-06-11 21:15:39 |
|