CVE-2013-1331
microsoft office
Published 12 Jun 2013 · updated 16 Jun 2026 · Analyzed
7.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 8 Jun 2022, with a remediation deadline of 22 Jun 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."
References
- www.us-cert.gov/ncas/alerts/TA13-168A · Third Party Advisory, US Government Resource
- docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-051 · Patch, Vendor Advisory
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16713 · Broken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16732 · Broken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-1331 · US Government Resource