(MS13-091) Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2885093)

  Severity: HIGH
  CVE Identifier: CVE-2013-0082,CVE-2013-1324,CVE-2013-1325
  Advisory Date: NOV 21, 2013

  DESCRIPTION

This update addresses three vulnerabilities found in MS Office programs. The vulnerabilities exist in the way the programs interprets specially crafted files. An attacker who successfully exploits these vulnerabilities could remotely execute any code on the vulnerable computer.

  SOLUTION

  AFFECTED SOFTWARE AND VERSION

  • Microsoft Office 2003 Service Pack 3
  • Microsoft Office 2007 Service Pack 3
  • Microsoft Office 2010 Service Pack 1 (32-bit editions)
  • Microsoft Office 2010 Service Pack 2 (32-bit editions)
  • Microsoft Office 2010 Service Pack 1 (64-bit editions)
  • Microsoft Office 2010 Service Pack 2 (64-bit editions)
  • Microsoft Office 2013 (32-bit editions)
  • Microsoft Office 2013 (64-bit editions)
  • Microsoft Office 2013 RT