MS13-086: Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2885084)

This script is Copyright (C) 2013-2014 Tenable Network Security, Inc.


Synopsis :

The Microsoft Office component installed on the remote host is affected
by multiple remote code execution vulnerabilities.

Description :

The remote Windows host is running a version of Microsoft Office or
Microsoft Office Compatibility Pack that is affected by multiple remote
code execution vulnerabilities. The vulnerabilities exist in the way
that Microsoft Word parses specially crafted files.

An attacker who successfully exploited these issues could take complete
control of an affected system and potentially execute remote code.

See also :

https://technet.microsoft.com/en-us/security/bulletin/ms13-086

Solution :

Microsoft has released a set of patches for Office 2003, 2007, and
Office Compatibility Pack.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.1
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 70338 ()

Bugtraq ID: 62827
62832

CVE ID: CVE-2013-3891
CVE-2013-3892