Summary
This host is missing a important security update according to Microsoft Bulletin MS13-043.
Impact
Successful exploitation could allow attackers to execute arbitrary code by tricking a user into opening a specially crafted word and RTF files.
Impact Level: System/Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/ms13-043
Insight
The flaw is due to an error when parsing Rich Text Format (RTF) data related to the listoverridecount and can be exploited to corrupt memory.
Affected
Microsoft Word 2003 Service Pack 3 and prior
References
Severity
Classification
-
CVE CVE-2013-1335 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Flaw in Microsoft VM Could Allow Code Execution (810030)
- Microsoft Internet Explorer Multiple Code Execution Vulnerabilities (974455)
- Microsoft Active Accessibility Remote Code Execution Vulnerability (2623699)
- Consent User Interface Privilege Escalation Vulnerability (2442962)
- Buffer Overrun in the ListBox and in the ComboBox (824141)