Vulnerability record · CVE-2013-1331 · published 12 June 2013
CVE-2013-1331: Microsoft Office buffer overflow via crafted PNG data
Microsoft · Office
Microsoft Office 2003 SP3 and Office 2011 for Mac contain a classic buffer overflow (CWE-120) triggered by crafted PNG data embedded in an Office document, caused by improper memory allocation. Successful exploitation allows arbitrary code execution in the context of the user who opens the document.
Description
Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows remote code execution, is listed in CISA KEV as actively exploited, and has a very high EPSS score, though exploitation requires user interaction to open a malicious document.
What it is
Microsoft Office 2003 SP3 and Office 2011 for Mac contain a classic buffer overflow (CWE-120) triggered by crafted PNG data embedded in an Office document, caused by improper memory allocation. Successful exploitation allows arbitrary code execution in the context of the user who opens the document.
Impact
An attacker who gets a victim to open a malicious Office document can execute arbitrary code with the victim's privileges, potentially leading to full system compromise.
Attack surface
Reached locally when a user opens a crafted Office document containing malicious PNG data; the CVSS vector (AV:L/PR:N/UI:R) indicates no authentication is required but user interaction is needed to open the file.
Exploitation
CVE-2013-1331 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-08), indicating active exploitation in the wild. EPSS 30-day probability is 0.81877 (99.63rd percentile), reflecting very high predicted exploitation likelihood.
What to do
- Apply the Microsoft security update referenced in MS13-051 (patch first).
- Disable or block opening of untrusted Office documents, especially from email or web downloads.
- Use Microsoft Office File Block and Protected View settings to prevent automatic processing of potentially malicious content.
- Remove or upgrade unsupported Office 2003 SP3 and Office 2011 for Mac installations where feasible.
Detection
- Monitor for Office processes (WINWORD.EXE, EXCEL.EXE) spawning child processes such as cmd.exe, powershell.exe, or wscript.exe.
- Inspect Office documents for embedded PNG files with anomalous size or structure that could trigger memory corruption.
- Review endpoint logs for crashes or memory access violations in Office applications when opening documents.
- Hunt for known exploit document hashes or indicators associated with CVE-2013-1331 in email and file transfer logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2013-1331 to the Known Exploited Vulnerabilities catalog on 8 June 2022 as "Microsoft Office Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 22 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.us-cert.gov/ncas/alerts/TA13-168A | Third Party AdvisoryUS Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-051 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16713 | Broken Link |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16732 | Broken Link |
| http://www.us-cert.gov/ncas/alerts/TA13-168A | Third Party AdvisoryUS Government Resource |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-051 | PatchVendor Advisory |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16713 | Broken Link |
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16732 | Broken Link |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-1331 | US Government Resource |
Track CVE-2013-1331 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-1331), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.