VulnerabilityModified
CVE-2013-1335
Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."
HIGH 9.3EPSS 20.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 20.93% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- microsoft/word · microsoft/word viewer
- Source
- secure@microsoft.com
References
- http://www.us-cert.gov/ncas/alerts/TA13-134AUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-043
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16229
- http://www.us-cert.gov/ncas/alerts/TA13-134AUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-043
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16229
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.