9.3

CVE-2013-3870

Exploit

Double free vulnerability in Microsoft Outlook 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to execute arbitrary code by including many nested S/MIME certificates in an e-mail message, aka "Message Certificate Vulnerability."

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftOutlook Version2007 Updatesp3
MicrosoftOutlook Version2010 Updatesp1 HwPlatformx64
MicrosoftOutlook Version2010 Updatesp1 SwPlatformx86
MicrosoftOutlook Version2010 Updatesp2 HwPlatformx64
MicrosoftOutlook Version2010 Updatesp2 SwPlatformx86
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 36.72% 0.97
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C