← Vulnerability feed

Vulnerability record · CVE-2013-0081 · published 11 September 2013

CVE-2013-0081: Microsoft SharePoint unassigned workflow handling denial of service

Microsoft · Sharepoint Foundation

SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1/SP2, and 2013 fail to properly process unassigned workflows. A crafted URL can hang the W3WP worker process, causing a denial of service. The flaw is an input validation issue (CWE-20) reachable over the network without authentication.

5.0 CVSS 2.0 Medium EPSS 77% · top 0.5% CWE-20 · Improper input validation
5.0CVSS 2.0 base score
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 do not properly process unassigned workflows, which allows remote attackers to cause a denial of service (W3WP process hang) via a crafted URL, aka "SharePoint Denial of Service Vulnerability."

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityUnauthenticated remote denial of service with partial availability impact, but no confirmed in-the-wild exploitation and only a medium CVSS 2.0 score.

What it is

SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1/SP2, and 2013 fail to properly process unassigned workflows. A crafted URL can hang the W3WP worker process, causing a denial of service. The flaw is an input validation issue (CWE-20) reachable over the network without authentication.

Impact

An unauthenticated remote attacker can hang the W3WP process, making the affected SharePoint site or service unavailable to legitimate users. The CVSS 2.0 vector shows partial availability impact only, with no confidentiality or integrity loss.

Attack surface

Reached over the network via a crafted URL against a SharePoint endpoint that handles unassigned workflows. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware usage is documented in the record. EPSS is high (0.76746, 99.5th percentile), suggesting elevated likelihood of attempted exploitation, but the record does not confirm in-the-wild activity.

What to do

  • Apply Microsoft security bulletin MS13-067 for the affected SharePoint versions.
  • Restrict network access to SharePoint workflow endpoints to trusted users and networks where feasible.
  • Monitor W3WP process health and configure automatic recycling or recovery to limit hang duration.
  • Retire or isolate unsupported SharePoint 2003/2007 deployments that cannot be patched.

Detection

  • Alert on W3WP process hangs, unresponsiveness, or unexpected worker process recycling on SharePoint servers.
  • Review IIS and SharePoint logs for crafted or anomalous URLs targeting workflow endpoints.
  • Baseline normal workflow request patterns and flag unusual unassigned-workflow requests.
  • Correlate repeated availability failures on SharePoint front ends with source IPs for triage.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-0081 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-58644Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker execute code. The flaw is rated CVSS 9.8 critica…KEVEPSS 16%analysed9.8CVE-2026-56164Microsoft SharePoint Server missing authentication allows privilege elevationMicrosoft Office SharePoint Server contains a missing authentication flaw in a critical function (CWE-306), letting an unauthenticated attacker reach…KEVEPSS 1.0%analysed9.8CVE-2026-50522Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 3.0%analysed9.8CVE-2026-20963Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 30%analysed9.8CVE-2025-53770Microsoft SharePoint Server deserialization RCE under active exploitationOn-premises Microsoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker run code on the server. Microsoft st…KEVEPSS 100%analysed9.8CVE-2023-29357Microsoft SharePoint Server elevation of privilege via authentication bypassCVE-2023-29357 is a critical elevation of privilege flaw in Microsoft SharePoint Server. The CVSS vector shows it is network reachable with no privil…KEVEPSS 100%analysed9.8CVE-2019-0604Microsoft SharePoint application package markup validation RCEMicrosoft SharePoint fails to validate the source markup of an application package, allowing crafted packages to execute code on the server. This is …KEVEPSS 100%analysed9.1CVE-2026-55040Microsoft SharePoint weak authentication allows network security feature bypassMicrosoft SharePoint Server contains a weak authentication flaw (CWE-1390) that lets an unauthorized attacker bypass a security feature over the netw…KEVEPSS 18%analysed

Source: NIST National Vulnerability Database (record CVE-2013-0081), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.