CVE-2013-1331 KEV
7.8
HIGH · CVSS 3.1 · EPSS 79.8% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-22.
Description
Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 79.82% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-120 |
| On CISA KEV | yes — remediate by 2022-06-22 |
| Public exploit | none known |
| Published | 2013-06-12 |
| Last modified | 2026-06-16 |
CISA KEV
| Name | Microsoft Office Buffer Overflow Vulnerability |
|---|---|
| Added | 2022-06-08 |
| Due | 2022-06-22 |
| Vendor / product | Microsoft / Office |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | office |
References
- http://www.us-cert.gov/ncas/alerts/TA13-168A
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-051
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16713
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16732
- http://www.us-cert.gov/ncas/alerts/TA13-168A
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-051
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16713
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16732
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-1331
→ the Explorer · watch your stack · NVD