First published: Wed Sep 11 2013(Updated: )
Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3847, CVE-2013-3849, and CVE-2013-3858.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Web Apps | =2010-sp1 | |
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft Office Word | =2003-sp3 | |
Microsoft Office Word | =2007-sp3 | |
Microsoft Office Word | =2010-sp1 | |
Microsoft Office Word Viewer | ||
Microsoft SharePoint Server 2010 | =2010-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3848 is rated as critical due to its potential for remote code execution.
To remediate CVE-2013-3848, apply the latest security updates provided by Microsoft for the affected software.
CVE-2013-3848 affects various versions of Microsoft Word, Office Web Apps, SharePoint Server, and the Office Compatibility Pack.
Yes, CVE-2013-3848 can cause denial of service due to memory corruption.
Remote attackers can exploit CVE-2013-3848 to execute arbitrary code on vulnerable systems.