CVE-2013-1331highunder attackCWE-120

CVE-2013-1331

Published · Updated

73Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 7.8epss 80%
from disclosure to weapon
Published on NVDJun 12
CISA KEV+3283d
exploitation probability
80%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2022-06-22

Apply updates per vendor instructions.

In short

Microsoft Office 2003 and 2011 for Mac contain a buffer overflow flaw when processing specially crafted PNG images in documents. An attacker can exploit this to run malicious code on a victim's computer by sending a document with a malicious image.

Technical detail

A buffer overflow vulnerability exists in PNG image processing within Microsoft Office 2003 SP3 and Office 2011 for Mac, triggered by improper memory allocation of crafted PNG data embedded in Office documents. Remote code execution is possible when a user opens a malicious document containing the affected PNG data; no additional privileges or user interaction beyond opening the document is required.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a