MS13-086: Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2885084)

This script is Copyright (C) 2013-2017 Tenable Network Security, Inc.

Synopsis :

The Microsoft Office component installed on the remote host is affected
by multiple remote code execution vulnerabilities.

Description :

The remote Windows host is running a version of Microsoft Office or
Microsoft Office Compatibility Pack that is affected by multiple remote
code execution vulnerabilities. The vulnerabilities exist in the way
that Microsoft Word parses specially crafted files.

An attacker who successfully exploited these issues could take complete
control of an affected system and potentially execute remote code.

See also :

Solution :

Microsoft has released a set of patches for Office 2003, 2007, and
Office Compatibility Pack.

Risk factor :

High / CVSS Base Score : 9.3
CVSS Temporal Score : 6.9
Public Exploit Available : false

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 70338 ()

Bugtraq ID: 62827

CVE ID: CVE-2013-3891

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now