KEVIntel
4.3
CVSS
Medium

CVE-2013-5054

PUBLISHED

Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an...

Exploited in the wild Remote
Vendor
Microsoft
Product
Office 2013
Published
Dec 11, 2013
EPSS

Automate this intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as exploited in the wild in 2013, aka "Token Hijacking Vulnerability."

CVSS scores

CVSS v2.0 4.3 Medium

AV:N/AC:M/Au:N/C:P/I:N/A:N

Exploitation status

Exploited in the wild

Recorded 2013-12-11 00:00:00 UTC · CVE

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CVE First 2013-12-11 00:00 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel