« Volver al listado

CVE-2013-5054

Estado: ModificadaMedia (4.3)—

Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as exploited in the wild in 2013, aka "Token Hijacking Vulnerability."

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-5054",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-12-11T00:55:04.067",
  "references": [
    {
      "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-104",
      "source": "secure@microsoft.com"
    },
    {
      "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-104",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as exploited in the wild in 2013, aka \"Token Hijacking Vulnerability.\""
    },
    {
      "lang": "es",
      "value": "Microsoft Office 2013 y 2013 RT permite a atacantes remotos descubrir los tokens de autenticación a través de respuestas manipuladas hacia una petición file-open en un archivo de Office de un sitio web, tal y como se explotó activamente en 2013, también conocida como \"Vulnerabilidad de secuestro de token\"."
    }
  ],
  "lastModified": "2026-06-16T23:58:19.020",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:office:2013:-:-:*:-:-:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "4CF73437-3617-4143-932A-47565106C16C"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:office:2013:-:-:*:-:-:x86:*",
              "vulnerable": true,
              "matchCriteriaId": "6E3190C1-7A52-4F68-B5C0-E0A9EC051627"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:office_2013_rt:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D33A5EFD-A587-44CE-B9F2-DBE8EC7C686F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}