CVE-2013-3849: Buffer Overflow
Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3847, CVE-2013-3848, and CVE-2013-3858.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3849?
CVE-2013-3849 is rated as critical due to its potential to allow remote attackers to execute arbitrary code or cause a denial of service.
How do I fix CVE-2013-3849?
To mitigate CVE-2013-3849, apply the appropriate security updates released by Microsoft for the affected versions of software.
What versions of Microsoft products are affected by CVE-2013-3849?
CVE-2013-3849 affects Microsoft Word 2003, 2007, 2010, Office Compatibility Pack SP3, Word Viewer, and SharePoint Server 2010 SP1 among others.
What are the potential impacts of CVE-2013-3849?
Exploitation of CVE-2013-3849 could lead to arbitrary code execution or a denial of service due to memory corruption.
Is there a workaround for CVE-2013-3849?
While the best defense is to apply patches, users can also consider restricting access to vulnerable services as a temporary measure.