CVE Number | Vulnerability | Product | Severity | Date |
---|---|---|---|---|
MS13-042 | Vulnerabilities in Microsoft Publisher Could Allow Remote Code Execution (2830397) | Microsoft Office | Important | 15-05-2013 |
Technical Information
Brief overview of the risk:
This security update resolves eleven privately reported vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user open a specially crafted Publisher file with an affected version of Microsoft Publisher.
Detailed Information on the risk:
Multiple remote code execution vulnerabilities exists in the way that Microsoft Publisher parses Publisher files. An attacker who successfully exploited any of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Further information on this exploit is available at : MS13-042
Affected Software
Microsoft Office 2003 Service Pack 3Microsoft Office 2007 Service Pack 3
Microsoft Office 2010 Service Pack 1 (32-bit editions)
Microsoft Office 2010 Service Pack 1 (64-bit editions)