Vulnerabilities > CVE-2013-3870 - Resource Management Errors vulnerability in Microsoft Outlook 2007/2010
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Double free vulnerability in Microsoft Outlook 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to execute arbitrary code by including many nested S/MIME certificates in an e-mail message, aka "Message Certificate Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
Common Weakness Enumeration (CWE)
Msbulletin
bulletin_id | MS13-068 |
bulletin_url | |
date | 2013-09-10T00:00:00 |
impact | Remote Code Execution |
knowledgebase_id | 2756473 |
knowledgebase_url | |
severity | Critical |
title | Vulnerability in Microsoft Outlook Could Allow Remote Code Execution |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS13-068.NASL |
description | The Outlook component of Microsoft Office is affected by a remote code execution vulnerability due to a flaw in how Outlook parses S/MIME messages. It is possible for a remote attacker to execute arbitrary code if a user opens or previews a specially crafted email in an affected version of Outlook. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 69828 |
published | 2013-09-11 |
reporter | This script is Copyright (C) 2013-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/69828 |
title | MS13-068: Vulnerability in Microsoft Outlook Could Allow Remote Code Execution (2756473) |
code |
|
Oval
accepted | 2013-10-28T04:00:36.480-04:00 | ||||||||||||
class | vulnerability | ||||||||||||
contributors |
| ||||||||||||
definition_extensions |
| ||||||||||||
description | Double free vulnerability in Microsoft Outlook 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to execute arbitrary code by including many nested S/MIME certificates in an e-mail message, aka "Message Certificate Vulnerability." | ||||||||||||
family | windows | ||||||||||||
id | oval:org.mitre.oval:def:18857 | ||||||||||||
status | accepted | ||||||||||||
submitted | 2013-09-13T17:32:25 | ||||||||||||
title | Message Certificate Vulnerability (CVE-2013-3870) - MS13-068 | ||||||||||||
version | 12 |
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 62188 CVE(CAN) ID: CVE-2013-3870 Microsoft Outlook是Office套件所捆绑的邮件客户端。 Microsoft Outlook 分析特制 S/MIME 电子邮件的方式中存在一个远程执行代码漏洞。成功利用此漏洞的攻击者可以完全控制受影响的系统。攻击者可随后安装程序;查看、更改或删除数据;或者创建拥有完全用户权限的新帐户。 0 Microsoft Office 2010 Microsoft Office 2007 Microsoft Outlook 2010 Microsoft Outlook 2007 SP2 Microsoft Outlook 2007 SP1 厂商补丁: Microsoft --------- Microsoft已经为此发布了一个安全公告(MS13-068)以及相应补丁: MS13-068:Vulnerability in Microsoft Outlook Could Allow Remote Code Execution (2756473) 链接:http://technet.microsoft.com/security/bulletin/MS13-068 |
id | SSV:61008 |
last seen | 2017-11-19 |
modified | 2013-09-14 |
published | 2013-09-14 |
reporter | Root |
title | Microsoft Outlook 远程代码执行漏洞(CVE-2013-3870)(MS13-068) |
References
- http://blogs.technet.com/b/srd/archive/2013/09/10/assessing-risk-for-the-september-2013-security-updates.aspx
- http://blogs.technet.com/b/srd/archive/2013/09/10/ms13-068-a-difficult-to-exploit-double-free-in-outlook.aspx
- http://www.us-cert.gov/ncas/alerts/TA13-253A
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18857
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-068