← Back to CVE List
Vulnerability Intelligence Report

CVE-2013-1330

The default configuration of Microsoft SharePoint Portal Server 2003 SP3, SharePoint Server 2007 SP3 and 2010 SP1 and SP2, and Office Web Apps 2010 does not set the EnableViewStateMac attribute, which allows remote attackers to execute arbitrary code by leveraging an unassigned workflow, aka "MAC Disabled Vulnerability."

No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:27.41%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
microsoft sharepoint_foundation 2010
microsoft sharepoint_portal_server 2003
microsoft sharepoint_server 2007, 2010
microsoft sharepoint_services 2.0, 3.0
microsoft office_web_apps 2010

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
27.411%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2013-01-12T00:00:00
Published2013-09-11T10:00:00
Patch Date2013-09-10
Last Updated2024-08-06T14:57:05

LINK COPIED TO CLIPBOARD