CVE-2013-0007

Microsoft Xml Core Services - Code Injection

Title source: rule
STIX 2.1

Description

Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML XSLT Vulnerability."

Exploits (1)

nomisec WORKING POC
by jyyjw · poc
https://github.com/jyyjw/msxml4-remediation

Scores

EPSS 0.2421
EPSS Percentile 96.1%

Details

CWE
CWE-94
Status published
Products (21)
microsoft/expression_web
microsoft/expression_web 2
microsoft/groove_server 2007 sp2 (2 CPE variants)
microsoft/office 2003 sp3
microsoft/office 2007 sp2 (2 CPE variants)
microsoft/office_compatibility_pack (2 CPE variants)
microsoft/sharepoint_server 2007 sp2 (2 CPE variants)
microsoft/windows_7 (2 CPE variants)
microsoft/windows_8
microsoft/windows_rt
... and 11 more
Published Jan 09, 2013
Tracked Since Feb 18, 2026