CVE-2013-1331 is a critical buffer overflow vulnerability affecting Microsoft Office 2003 SP3 and Office 2011 for Mac, allowing remote code execution through specially crafted PNG data within Office documents. With a CVSS score of 7.8 (HIGH) and an EPSS score indicating high exploitability, this flaw presents a significant risk due to its low attack complexity and potential for complete compromise of confidentiality, integrity, and availability. This vulnerability has been actively exploited in the wild, as confirmed by its presence in the KEV catalog, and has garnered substantial community discussion, despite a lack of public exploit code on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:* | ||
2011CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2011:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.