CVE-2013-3870

Microsoft Outlook 2007 SP3, 2010 SP1, and SP2 - Remote Code Execution via Nested S/MIME Certificates

Title source: llm
STIX 2.1

Description

Double free vulnerability in Microsoft Outlook 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to execute arbitrary code by including many nested S/MIME certificates in an e-mail message, aka "Message Certificate Vulnerability."

References (5)

Core 5

Scores

EPSS 0.1864
EPSS Percentile 97.0%

Details

CWE
CWE-399
Status published
Products (2)
microsoft/outlook 2007 sp3
microsoft/outlook 2010 sp1 (4 CPE variants)
Published Sep 11, 2013
Tracked Since Feb 18, 2026