CVE-2013-0006

Description

Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka MSXML Integer Truncation Vulnerability.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
69.423

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Microsoft XML Core Services 4.0 Service Pack 3 (KB2758694)Windows
Security Update for Microsoft XML Core Services 4.0 Service Pack 3 (KB2758694) x64 bases systemsWindows
Security Update for Windows XP (KB2757638)Windows
Security Update for Windows Vista (KB2757638)Windows
Security Update for Windows Server 2008 (KB2757638)Windows
Security Update for Windows 7 (KB2757638) x86 based systemsWindows
Security Update for Windows 7 (KB2757638) x86 based systems for SP1Windows
Security Update for Windows XP x64 Edition (KB2757638)Windows
Security Update for Windows Server 2003 x64 Edition (KB2757638)Windows
Security Update for Windows Vista for x64-based Systems (KB2757638)Windows
Security Update for Windows Server 2008 x64 Edition (KB2757638)Windows
Security Update for Windows 7 for x64-based Systems (KB2757638)Windows
Security Update for Windows 7 for x64-based Systems (KB2757638) for SP1Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB2757638)Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB2757638) for SP1Windows
Security Update for Windows 8 (KB2757638)Windows
Security Update for Windows 8 for x64-based Systems (KB2757638)Windows
Security Update for Windows Server 2012 (KB2757638)Windows
Security Update for Microsoft XML Core Services 6.0 Service Pack 2 (KB2758696)Windows
Security Update for Microsoft XML Core Services 6.0 Service Pack 2 for x64-based Systems (KB2758696)Windows
Security Update for Microsoft Office 2007 suites (KB2687499)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-12892Security Update for Microsoft XML Core Services 4.0 Service Pack 3 (KB2758694)
PATCH-12893Security Update for Microsoft XML Core Services 4.0 Service Pack 3 (KB2758694)
PATCH-12895Security Update for Windows Vista (KB2757638)
PATCH-12896Security Update for Windows Server 2008 (KB2757638)
PATCH-12897Security Update for Windows 7 (KB2757638)
PATCH-12898Security Update for Windows 7 (KB2757638)
PATCH-12899Security Update for Windows XP x64 Edition (KB2757638)
PATCH-12900Security Update for Windows Server 2003 x64 Edition (KB2757638)
PATCH-12901Security Update for Windows Vista for x64-based Systems (KB2757638)
PATCH-12902Security Update for Windows Server 2008 x64 Edition (KB2757638)
PATCH-12903Security Update for Windows 7 for x64-based Systems (KB2757638)
PATCH-12904Security Update for Windows 7 for x64-based Systems (KB2757638)
PATCH-12905Security Update for Windows Server 2008 R2 x64 Edition (KB2757638)
PATCH-12906Security Update for Windows Server 2008 R2 x64 Edition (KB2757638)
PATCH-12907Security Update for Windows 8 (KB2757638)
PATCH-12908Security Update for Windows 8 for x64-based Systems (KB2757638)
PATCH-12909Security Update for Windows Server 2012 (KB2757638)
PATCH-12910Security Update for Microsoft XML Core Services 6.0 Service Pack 2 (KB2758696)
PATCH-12911Security Update for Microsoft XML Core Services 6.0 Service Pack 2 for x64-based Systems (KB2758696)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234