Lucene search

K
mskbMicrosoftKB2885089
HistoryOct 08, 2013 - 12:00 a.m.

MS13-084: Vulnerabilities in Microsoft SharePoint Server could allow remote code execution: October 8, 2013

2013-10-0800:00:00
Microsoft
support.microsoft.com
41

EPSS

0.877

Percentile

98.7%

<html><body><p>This security update addresses the vulnerabilities by correcting how affected Microsoft software validates data when parsing specially crafted Office files and by changing configuration of SharePoint pages to help provide additional protection against clickjacking attacks.</p><h2>INTRODUCTION</h2><div>Microsoft has released security bulletin MS13-084. To view the complete security bulletin, visit one of the following Microsoft websites: <ul><li>Home users:<div><a href=“http://www.microsoft.com/security/pc-security/updates.aspx” target=“_self”>http://www.microsoft.com/security/pc-security/updates.aspx</a></div><span>Skip the details</span>: Download the updates for your home computer or laptop from the Microsoft Update website now:<br /><div><a href=“http://update.microsoft.com/microsoftupdate/” target=“_self”>http://update.microsoft.com/microsoftupdate/</a></div></li><li>IT professionals:<div><a href=“http://technet.microsoft.com/security/bulletin/ms13-084” target=“_self”>http://technet.microsoft.com/security/bulletin/MS13-084</a></div></li></ul><h3>How to obtain help and support for this security update</h3> Help installing updates: <a href=“https://support.microsoft.com/ph/6527” target=“_self”>Support for Microsoft Update</a><br /><br />Security solutions for IT professionals: <br /><a href=“http://technet.microsoft.com/security/bb980617.aspx” target=“_self”>TechNet Security Troubleshooting and Support</a><br /><br />Help protect your computer that is running Windows from viruses and malware:<br /><a href=“https://support.microsoft.com/contactus/cu_sc_virsec_master” target=“_self”>Virus Solution and Security Center</a><br /><br />Local support according to your country: <br /><a href=“https://support.microsoft.com/common/international.aspx” target=“_self”>International Support</a><br /><br /></div><h2></h2><div><h3>Known issues and additional information about this security update</h3> <br /> <br /><br /> The following articles contain additional information about this security update as it relates to individual product versions. The articles may contain known issue information. If this is the case, the known issue is listed below each article link.<br /><br /><br /><ul><li><a href=“https://support.microsoft.com/en-us/help/2589365”>2589365 </a> MS13-084: Description of the security update for SharePoint Foundation 2010 : October 8, 2013 </li><li><a href=“https://support.microsoft.com/en-us/help/2596741”>2596741 </a> MS13-084: Description of the security update for SharePoint Server 2007 and Windows SharePoint Services 3.0: October 8, 2013 </li><li><a href=“https://support.microsoft.com/en-us/help/2752002”>2752002 </a> MS13-084: Description of the security update for Excel Services in Microsoft SharePoint Server 2013: October 8, 2013</li><li><a href=“https://support.microsoft.com/en-us/help/2760561”>2760561 </a> MS13-084: Description of the security update for Microsoft SharePoint Server 2013 (pptserver): October 8, 2013</li><li><a href=“https://support.microsoft.com/en-us/help/2826022”>2826022 </a> MS13-084: Description of the security update for Word Automation Services in SharePoint Server 2010: October 8, 2013</li><li><a href=“https://support.microsoft.com/en-us/help/2826028”>2826028 </a> MS13-084: Description of the security update for Excel Online: October 8, 2013</li><li><a href=“https://support.microsoft.com/en-us/help/2826029”>2826029 </a> MS13-084: Description of the security update for Excel Services in Microsoft SharePoint Server 2010: October 8, 2013</li><li><a href=“https://support.microsoft.com/en-us/help/2826030”>2826030 </a> MS13-084: Description of the security update for Word Online: October 8, 2013</li><li><a href=“https://support.microsoft.com/en-us/help/2826036”>2826036 </a> MS13-084: Description of the security update for Word Automation Services in Microsoft SharePoint Server 2013: October 8, 2013</li><li><a href=“https://support.microsoft.com/en-us/help/2827222”>2827222 </a> MS13-084: Description of the security update for Microsoft SharePoint Server 2013 (wacserver): October 8, 2013</li><li><a href=“https://support.microsoft.com/en-us/help/2827327”>2827327 </a> MS13-084: Description of the security update for Excel Services in Microsoft Office SharePoint Server 2007: October 8, 2013</li></ul></div><h2>More Information</h2><div><div><div><div><span><span></span></span><span><span>File hash information</span></span></div><div><span><div><div><table><tr><th>File name</th><th>SHA1 hash</th><th>SHA256 hash</th></tr><tr><td>pptserver2013-kb2760561-fullfile-x64-glb.exe</td><td>040B3D76602BEC08412A9AC5799FC7822FD56993</td><td>6CFE398A9CA400F50533CDBF7F3E04449D03147C73BD7D68A6304D4B2FBB994B</td></tr><tr><td>wac2010-kb2826030-fullfile-x64-glb.exe</td><td>F73CE958EFE0FE82D93E4D7F7688688E6941289F</td><td>5FA71B9D7C9EBEB34718DEE7E2BB9BB57698F91ED2CA2DBEC6635EECB8A1C22D</td></tr><tr><td>wacserver2013-kb2827222-fullfile-x64-glb.exe</td><td>BE01CFF5155299AB9D8EC5124714F22D71F5E7C3</td><td>FD71763DC989ABC97D8B84532D843BACD0C0BF6DE19216873BE11D9A1766D113</td></tr><tr><td>wdsrv2010-kb2826022-fullfile-x64-glb.exe</td><td>47038AC2AD594B48CD38B29001CCFAC2D4BD0C05</td><td>60D77382AF7AEFD5C3BB5A6F74608043D35A44DCDBADEC0E2332552BFC37AB79</td></tr><tr><td>wdsrv2013-kb2826036-fullfile-x64-glb.exe</td><td>91AD5069AD320425E5D2C84A76F1AE69A0B09AF4</td><td>2BBFB3CE6045E435ADDA1A472B46966D0B0EA5BE4FDD5F9537C6B9A128D9C6B8</td></tr><tr><td>wssloc2007-kb2596741-fullfile-x64-glb.exe</td><td>6039A3FB80203701160C46ADCF723D03D12B2269</td><td>2AC4721CA040B37656DD641F553C29451741670B83A1D8FA6A30F6B750C9A3BB</td></tr><tr><td>wssloc2007-kb2596741-fullfile-x86-glb.exe</td><td>9B863359A94C17D640AE8FDE91219E792EEA7E4D</td><td>C8AFFA076AFB63FEB7ECBA3D3B8C2B448CC5E67D606EA4189D91CA9ED329C202</td></tr><tr><td>wssloc2010-kb2589365-fullfile-x64-glb.exe</td><td>38787214BBA3572349807239100BC3B39FA39DEF</td><td>D6987C1D954E42F6FB377F657C45117B8E0A0A38FC2CA58F22A42883C67B268D</td></tr><tr><td>xlsrv2010-kb2826029-fullfile-x64-glb.exe</td><td>2232EACC4DAC74F290506A0E1A81A322E9AEC194</td><td>1E60CC3200C7642AC28ECB1A486C85E97EEC61887E2E8ED2CDB49BDF03CDBB5D</td></tr><tr><td>xlsrvapp2007-kb2827327-fullfile-x64-glb.exe</td><td>6D323AA332308DA731CC2001C47F1571D9017AAE</td><td>EE74293BF73C363361F5F3E077D7B39EAFF135116FD75C2893F7D2281FB9551A</td></tr><tr><td>xlsrvloc2013-kb2752002-fullfile-x64-glb.exe</td><td>760196D5FF10186F6921A1C1BBFAE477E4C7CCFF</td><td>746166E62DEA0DA09C368E63F6E5900BDF1A649C71EFE740E19EBEF5EAEC0153</td></tr><tr><td>xlwac2010-kb2826028-fullfile-x64-glb.exe</td><td>5CC39A773393684B01C9862D8F615949645B7539</td><td>EDB40B1A7132CD95246A96A9CC2505754E2F46554F1FB559BDE02EA1563FEDEA</td></tr></table></div></div><br /></span></div></div></div></div><h2>Applies to</h2><div>This article applies to the following:<ul><li>Microsoft SharePoint Server 2013 </li><li>Microsoft SharePoint Foundation 2013 </li><li>Microsoft SharePoint Server 2010 Service Pack 2 </li><li>Microsoft SharePoint Server 2010 Service Pack 1 </li><li>Microsoft SharePoint Foundation 2010 </li><li>Microsoft SharePoint Server 2007 </li><li>Microsoft Windows SharePoint Services 3.0 </li><li>Microsoft Windows SharePoint Services 2.0 </li><li>Excel Services in Microsoft SharePoint Server 2010 </li><li>Excel Services in Microsoft Office SharePoint Server 2007 </li><li>Word Automation Services in SharePoint Server 2013</li><li>Word Automation Services in SharePoint Server 2010 </li><li>Microsoft Excel Online </li><li>Microsoft Word Online </li></ul></div></body></html>