First published: Wed Sep 11 2013(Updated: )
Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3847, CVE-2013-3848, and CVE-2013-3858.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint | =sp3 | |
Microsoft Word for Android | =2003-sp3 | |
Microsoft Word for Android | =2007-sp3 | |
Microsoft Word for Android | =2010-sp1 | |
Microsoft Word for Android | =2010-sp1 | |
Microsoft Word Viewer | ||
Microsoft SharePoint Server | =2010-sp1 | |
Microsoft Office Web Apps | =2010-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3849 is rated as critical due to its potential to allow remote attackers to execute arbitrary code or cause a denial of service.
To mitigate CVE-2013-3849, apply the appropriate security updates released by Microsoft for the affected versions of software.
CVE-2013-3849 affects Microsoft Word 2003, 2007, 2010, Office Compatibility Pack SP3, Word Viewer, and SharePoint Server 2010 SP1 among others.
Exploitation of CVE-2013-3849 could lead to arbitrary code execution or a denial of service due to memory corruption.
While the best defense is to apply patches, users can also consider restricting access to vulnerable services as a temporary measure.