CVE-2013-5057 is a vulnerability in the hxds.dll component of Microsoft Office 2007 SP3 and Office 2010 SP1/SP2. This flaw stems from the lack of Address Space Layout Randomization (ASLR) implementation, making it easier for attackers to execute arbitrary code. The vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and potential for partial integrity impact, requiring user interaction via a crafted website visited with Internet Explorer. This vulnerability was actively exploited in the wild in December 2013, though no public exploit code or significant community discussion is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2007:sp3:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp1:x64:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp1:x86:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp2:x64:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2010:sp2:x86:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.