Oval Definition:oval:org.mitre.oval:def:19162
Revision Date:2014-04-07Version:19
Title:Word Stack Buffer Overwrite Vulnerability in Microsoft Office (CVE-2013-1324) - MS13-091
Description:Stack-based buffer overflow in Microsoft Office 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT allows remote attackers to execute arbitrary code via a crafted WordPerfect document (.wpd) file, aka "Word Stack Buffer Overwrite Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2013-1324
Platform(s):Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Microsoft Office 2003
Microsoft Office 2007
Microsoft Office 2010
Microsoft Office 2013
Definition Synopsis
  • For Office 2007 and its vulnerable file
  • Microsoft Office 2007 SP3 is installed
  • AND Check if the version of Wpft532.cnv is greater than or equal to 2006.1200.0000.0000
  • AND Check if the version of Wpft532.cnv is less than 2006.1200.6659.5000
  • OR For Office 2003 and its vulnerable file
  • Microsoft Office 2003 SP3 is installed
  • AND Check if the version of MSCONV97.DLL is less than 2003.1100.8327.0
  • OR For Office 2010 and its vulnerable file
  • For Office 2010
  • Microsoft Office 2010 SP1 is installed
  • OR Microsoft Office 2010 SP2 is installed
  • AND Check if the version of Wpft532.cnv is greater than or equal 2010.1400.0000.0000
  • AND Check if the version of Wpft532.cnv is less than 2010.1400.7011.1000
  • OR For Office 2013 and its vulnerable file
  • Microsoft Office 2013 is installed
  • AND Check if the version of Wpft532.cnv is greater than or equal to 2012.1500.0000.0000 and less than 2012.1500.4525.1000
  • BACK