Vulnerability record · CVE-2013-0081 · published 11 September 2013
CVE-2013-0081: Microsoft SharePoint unassigned workflow handling denial of service
Microsoft · Sharepoint Foundation
SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1/SP2, and 2013 fail to properly process unassigned workflows. A crafted URL can hang the W3WP worker process, causing a denial of service. The flaw is an input validation issue (CWE-20) reachable over the network without authentication.
Description
Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 do not properly process unassigned workflows, which allows remote attackers to cause a denial of service (W3WP process hang) via a crafted URL, aka "SharePoint Denial of Service Vulnerability."
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityUnauthenticated remote denial of service with partial availability impact, but no confirmed in-the-wild exploitation and only a medium CVSS 2.0 score.
What it is
SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1/SP2, and 2013 fail to properly process unassigned workflows. A crafted URL can hang the W3WP worker process, causing a denial of service. The flaw is an input validation issue (CWE-20) reachable over the network without authentication.
Impact
An unauthenticated remote attacker can hang the W3WP process, making the affected SharePoint site or service unavailable to legitimate users. The CVSS 2.0 vector shows partial availability impact only, with no confidentiality or integrity loss.
Attack surface
Reached over the network via a crafted URL against a SharePoint endpoint that handles unassigned workflows. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware usage is documented in the record. EPSS is high (0.76746, 99.5th percentile), suggesting elevated likelihood of attempted exploitation, but the record does not confirm in-the-wild activity.
What to do
- Apply Microsoft security bulletin MS13-067 for the affected SharePoint versions.
- Restrict network access to SharePoint workflow endpoints to trusted users and networks where feasible.
- Monitor W3WP process health and configure automatic recycling or recovery to limit hang duration.
- Retire or isolate unsupported SharePoint 2003/2007 deployments that cannot be patched.
Detection
- Alert on W3WP process hangs, unresponsiveness, or unexpected worker process recycling on SharePoint servers.
- Review IIS and SharePoint logs for crafted or anomalous URLs targeting workflow endpoints.
- Baseline normal workflow request patterns and flag unusual unassigned-workflow requests.
- Correlate repeated availability failures on SharePoint front ends with source IPs for triage.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-0081 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-0081), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.