CVE-2013-5054, known as the "Token Hijacking Vulnerability," affects Microsoft Office 2013 and 2013 RT. It allows remote attackers to discover authentication tokens when a user opens a specially crafted Office file from a website. This vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and potential for partial confidentiality impact, requiring no authentication. Although exploited in the wild in 2013, there is no public exploit code available, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013:-:-:*:-:-:x64:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2013:-:-:*:-:-:x86:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:office_2013_rt:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.