Description
Microsoft SharePoint Server 2010 SP1 and SP2 and 2013, and Office Web Apps 2013, allows remote attackers to execute arbitrary code via crafted page content, aka "SharePoint Page Content Vulnerabilities."
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-100
Scores
EPSS
0.1452
EPSS Percentile
96.2%
Details
CWE
CWE-94
Status
published
Products (3)
microsoft/office_web_apps
2013
microsoft/sharepoint_server
2010 sp1 (2 CPE variants)
microsoft/sharepoint_server
2013
Published
Dec 11, 2013
Tracked Since
Feb 18, 2026