CVE-2013-3854: Buffer Overflow
Published Sep 11, 2013
·Updated
Microsoft Office 2007 SP3 and Word 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3853.
Affected Software
2 affected components
Microsoft Office=2007-sp3
Microsoft Word=2007-sp3
Event History
Sep 11, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3854?
CVE-2013-3854 has a critical severity rating as it allows remote code execution and can lead to denial of service.
2
How do I fix CVE-2013-3854?
To fix CVE-2013-3854, users should apply the security updates provided by Microsoft for Office 2007 SP3.
3
What software is affected by CVE-2013-3854?
CVE-2013-3854 affects Microsoft Office 2007 SP3 and Microsoft Word 2007 SP3.
4
What type of vulnerability is CVE-2013-3854?
CVE-2013-3854 is classified as a memory corruption vulnerability.
5
Can CVE-2013-3854 be exploited without user interaction?
Yes, CVE-2013-3854 can be exploited by opening a specially crafted Office document, requiring no additional user interaction.