CVE-2013-1331
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Apply updates per vendor instructions.
Microsoft Office 2003 and 2011 for Mac contain a buffer overflow flaw when processing specially crafted PNG images in documents. An attacker can exploit this to run malicious code on a victim's computer by sending a document with a malicious image.
A buffer overflow vulnerability exists in PNG image processing within Microsoft Office 2003 SP3 and Office 2011 for Mac, triggered by improper memory allocation of crafted PNG data embedded in Office documents. Remote code execution is possible when a user opens a malicious document containing the affected PNG data; no additional privileges or user interaction beyond opening the document is required.
The full analysis of this CVE is available in Portuguese →