CVE-2013-1301: Infoleak
Published May 15, 2013
·Updated
Microsoft Visio 2003 SP3 2007 SP3, and 2010 SP1 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, aka "XML External Entities Resolution Vulnerability."
Affected Software
3 affected components
Microsoft Visio=2003-sp3
Microsoft Visio=2007-sp3
Microsoft Visio=2010-sp1
Event History
May 15, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1301?
CVE-2013-1301 has a moderate severity rating due to its potential for unauthorized file access.
2
How do I fix CVE-2013-1301?
To fix CVE-2013-1301, install the security update provided by Microsoft for the affected versions of Visio.
3
Which versions of Microsoft Visio are affected by CVE-2013-1301?
CVE-2013-1301 affects Microsoft Visio 2003 SP3, 2007 SP3, and 2010 SP1.
4
What type of vulnerability is CVE-2013-1301?
CVE-2013-1301 is classified as an XML External Entities Resolution Vulnerability.
5
Can CVE-2013-1301 be exploited remotely?
Yes, CVE-2013-1301 can be exploited remotely by attackers to read arbitrary files.