Remote Code Execution Vulnerability in Microsoft Publisher by Microsoft
CVE-2013-1316

Currently unrated

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
15 May 2013

What is CVE-2013-1316?

Microsoft Publisher 2003 SP3 contains a vulnerability due to improper size validation of an array, allowing remote attackers to execute arbitrary code by delivering a specially crafted Publisher file. This flaw highlights the importance of handling untrusted files carefully, as exploitation can lead to complete system compromise if the malicious file is opened by a user.

References

EPSS Score

59% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.