← Back to CVE List
Vulnerability Intelligence Report

CVE-2013-3889

Microsoft Excel 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office for Mac 2011; Excel Viewer; Office Compatibility Pack SP3; and Excel Services and Word Automation Services in SharePoint Server 2013 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Excel Memory Corruption Vulnerability."

No Active Exploit Signals
CVSS Base Score
9.3
HIGH
EPSS Probability:27.40%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
microsoft excel 2010, 2013
microsoft excel_viewer all
microsoft office 2007, 2010, 2011, 2013
microsoft office_2013_rt all
microsoft office_compatibility_pack all
microsoft office_web_apps 2010
microsoft sharepoint_server 2007, 2013, 2010

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
27.399%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2013-06-03T00:00:00
Published2013-10-09T14:44:00
Patch Date2013-10-08
Last Updated2024-08-06T16:22:01

LINK COPIED TO CLIPBOARD