CVE-2013-1323: Code Injection
Published May 15, 2013
·Updated
Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Incorrect NULL Value Handling Vulnerability."
Affected Software
1 affected component
Microsoft Publisher=2003-sp3
Event History
May 15, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1323?
CVE-2013-1323 is rated as critical due to its potential to allow remote code execution.
2
How do I fix CVE-2013-1323?
To fix CVE-2013-1323, users should apply the relevant security updates provided by Microsoft for Publisher 2003 SP3.
3
What are the potential impacts of CVE-2013-1323?
The potential impacts of CVE-2013-1323 include unauthorized remote code execution and system compromise.
4
Who is affected by CVE-2013-1323?
Users of Microsoft Publisher 2003 SP3 are vulnerable to CVE-2013-1323.
5
Can CVE-2013-1323 be exploited through email attachments?
Yes, CVE-2013-1323 can be exploited through specially crafted Publisher files sent via email.