Lucene search

K
cveMicrosoftCVE-2013-3850
HistorySep 11, 2013 - 2:03 p.m.

CVE-2013-3850

2013-09-1114:03:48
CWE-119
microsoft
web.nvd.nist.gov
119
microsoft word
memory corruption
cve-2013-3850
office document
remote code execution
denial of service

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.866

Percentile

98.6%

Microsoft Word 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka “Word Memory Corruption Vulnerability.”

Affected configurations

Nvd
Node
microsoftoffice_compatibility_packsp3
OR
microsoftwordMatch2003sp3
OR
microsoftwordMatch2007sp3
OR
microsoftwordMatch2010sp1
OR
microsoftwordMatch2010sp2x64
OR
microsoftwordMatch2010sp2x86
OR
microsoftword_viewer
VendorProductVersionCPE
microsoftoffice_compatibility_pack*cpe:2.3:a:microsoft:office_compatibility_pack:*:sp3:*:*:*:*:*:*
microsoftword2003cpe:2.3:a:microsoft:word:2003:sp3:*:*:*:*:*:*
microsoftword2007cpe:2.3:a:microsoft:word:2007:sp3:*:*:*:*:*:*
microsoftword2010cpe:2.3:a:microsoft:word:2010:sp1:*:*:*:*:*:*
microsoftword2010cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:*:x64:*
microsoftword2010cpe:2.3:a:microsoft:word:2010:sp2:*:*:*:x86:*:*
microsoftword_viewer*cpe:2.3:a:microsoft:word_viewer:*:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.866

Percentile

98.6%