MS13-085: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2885080)

This script is Copyright (C) 2013-2014 Tenable Network Security, Inc.


Synopsis :

The Microsoft Office component installed on the remote host is
affected by multiple remote code execution vulnerabilities.

Description :

The remote Windows host is running a version of Microsoft Office,
Microsoft Excel, Office Compatibility Pack, or Microsoft Excel Viewer
that is affected by remote code execution vulnerabilities in the way
that Microsoft Excel parses file contents. (CVE-2013-3889,
CVE-2013-3890).

If an attacker can trick a user on the affected host into opening a
specially crafted file, it may be possible to leverage these issues to
read arbitrary files on the target system or execute arbitrary code,
subject to the user's privileges.

See also :

http://technet.microsoft.com/en-us/security/bulletin/ms13-085

Solution :

Microsoft has released a set of patches for Excel 2007, Excel 2010,
Excel 2013, Office 2007, Office 2010, Office 2013, Excel Viewer, and
Office Compatibility Pack.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.1
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 70337 ()

Bugtraq ID: 62824
62829

CVE ID: CVE-2013-3889
CVE-2013-3890