CVE-2013-3889Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft Excel

Severity
9.3CRITICALNVD
EPSS
65.0%
top 1.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 9
Latest updateMay 14

Description

Microsoft Excel 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office for Mac 2011; Excel Viewer; Office Compatibility Pack SP3; and Excel Services and Word Automation Services in SharePoint Server 2013 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Excel Memory Corruption Vulnerability."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages4 packages

NVDmicrosoft/excel2010, 2013+1
NVDmicrosoft/office4 versions+3
NVDmicrosoft/sharepoint_server2007, 2010, 2013+2

🔴Vulnerability Details

2
GHSA
GHSA-qfg6-4gxh-j3wv: Microsoft Excel 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office for Mac 2011; Excel Viewer2022-05-14
CVEList
CVE-2013-3889: Microsoft Excel 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office for Mac 2011; Excel Viewer2013-10-09
CVE-2013-3889 — Microsoft Excel vulnerability | cvebase