cbcvebase.
CVE-2013-0006
published 2013-01-09

CVE-2013-0006: Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a…

PriorityP357high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
28.08%
97.9th percentile
Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability."

Affected

10 ranges
VendorProductVersion rangeFixed in
microsoftexpression_web
microsoftgroove_server
microsoftoffice
microsoftoffice
microsoftsharepoint_server
microsoftwindows_server_2008
microsoftxml_core_services
microsoftxml_core_services
microsoftxml_core_services
microsoftxml_core_services

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered via a crafted XML message/web page targeting MSXML parsing; monitor for anomalous XML content delivered to MSXML 3.0, 5.0, or 6.0 consumers
  • In ICS/OPC contexts, an attacker-controlled OPC XML-DA Server responding with a crafted XML message can trigger the vulnerability; monitor OPC XML-DA traffic for malformed/unexpected XML responses
  • The vulnerability is a stack-based buffer overflow triggered through numeric/integer truncation errors in XML parsing; look for stack-based buffer overflow indicators in processes consuming MSXML
  • ·No known public exploits specifically target this vulnerability as of the advisory date; exploitation requires attacker to control or spoof an OPC XML-DA server in the ICS context
  • ·Exploitation in the ICS scenario requires high attack complexity (CVSS AC:H), meaning the attacker must be in a position to intercept or control OPC XML-DA server responses
  • ·Affected OSIsoft PI Interface for OPC XML-DA scope is all versions prior to 1.7.3.x; MSXML affected versions are 3.0, 5.0, and 6.0

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.