CVE-2013-0006
published 2013-01-09CVE-2013-0006: Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a…
PriorityP357high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
28.08%
97.9th percentile
Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability."
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | expression_web | — | — |
| microsoft | groove_server | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | xml_core_services | — | — |
| microsoft | xml_core_services | — | — |
| microsoft | xml_core_services | — | — |
| microsoft | xml_core_services | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is triggered via a crafted XML message/web page targeting MSXML parsing; monitor for anomalous XML content delivered to MSXML 3.0, 5.0, or 6.0 consumers ↗
- →In ICS/OPC contexts, an attacker-controlled OPC XML-DA Server responding with a crafted XML message can trigger the vulnerability; monitor OPC XML-DA traffic for malformed/unexpected XML responses ↗
- →The vulnerability is a stack-based buffer overflow triggered through numeric/integer truncation errors in XML parsing; look for stack-based buffer overflow indicators in processes consuming MSXML ↗
- ·No known public exploits specifically target this vulnerability as of the advisory date; exploitation requires attacker to control or spoof an OPC XML-DA server in the ICS context ↗
- ·Exploitation in the ICS scenario requires high attack complexity (CVSS AC:H), meaning the attacker must be in a position to intercept or control OPC XML-DA server responses ↗
- ·Affected OSIsoft PI Interface for OPC XML-DA scope is all versions prior to 1.7.3.x; MSXML affected versions are 3.0, 5.0, and 6.0 ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
OSIsoft PI Interface for OPC XML-DA
cisa_ics·2020-11-10·CVSS 8.8
[HIGH] OSIsoft PI Interface for OPC XML-DA
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
OSIsoft PI Interface for OPC XML-DA
Last RevisedNovember 10, 2020
Alert CodeICSA-20-315-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.1
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: OSIsoft
- Equipment: PI Interface
- Vulnerability: Numeric Errors
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker-controlled OPC XML-DA Server to respond with a crafted XML message and exploit the PI Interface for OPC XML-DA, resulting in code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
All versions of PI Interface
VMware
VMware security updates for vCenter Server
vendor_vmware·2013-04-25·CVSS 7.2
CVE-2012-2337 [HIGH] VMware security updates for vCenter Server
VMSA-2013-0006: VMware security updates for vCenter Server
a. vCenter Server AD anonymous LDAP binding credential by-pass vCenter Server when deployed in an environment that uses Active Directory (AD) with anonymous LDAP binding enabled doesn't properly handle login credentials. In this environment, authenticating to vCenter Server with a valid user name and a blank password may be successful even if a non-blank password is required for the account. The issue is present on vCenter Server 5.1, 5.1a and 5.1b if AD anonymous LDAP binding is enabled. The issue is addressed in vCenter Server 5.1 Update 1 by removing the possibility to authenticate using blank passwords. This change in the authentication mechanism is present regardless if anonymous binding is enabled or not.
CVEs: CVE-2012-233
GHSA
GHSA-4jcp-w4pp-vm92: Microsoft XML Core Services (aka MSXML) 3
ghsa_unreviewed·2022-05-05
CVE-2013-0006 [HIGH] GHSA-4jcp-w4pp-vm92: Microsoft XML Core Services (aka MSXML) 3
Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability."
No detection rules found.
No writeups or analysis indexed.
http://www.us-cert.gov/cas/techalerts/TA13-008A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-002https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16429https://us-cert.cisa.gov/ics/advisories/icsa-20-315-01http://www.us-cert.gov/cas/techalerts/TA13-008A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-002https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16429https://us-cert.cisa.gov/ics/advisories/icsa-20-315-01
2013-01-09
Published