MS13-085: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2885080)

This script is Copyright (C) 2013-2016 Tenable Network Security, Inc.


Synopsis :

The Microsoft Office component installed on the remote host is
affected by multiple remote code execution vulnerabilities.

Description :

The remote Windows host is running a version of Microsoft Office,
Microsoft Excel, Office Compatibility Pack, or Microsoft Excel Viewer
that is affected by remote code execution vulnerabilities in the way
that Microsoft Excel parses file contents. (CVE-2013-3889,
CVE-2013-3890).

If an attacker can trick a user on the affected host into opening a
specially crafted file, it may be possible to leverage these issues to
read arbitrary files on the target system or execute arbitrary code,
subject to the user's privileges.

See also :

https://technet.microsoft.com/library/security/ms13-085

Solution :

Microsoft has released a set of patches for Excel 2007, Excel 2010,
Excel 2013, Office 2007, Office 2010, Office 2013, Excel Viewer, and
Office Compatibility Pack.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 6.9
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 70337 ()

Bugtraq ID: 62824
62829

CVE ID: CVE-2013-3889
CVE-2013-3890

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial