Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Vulnerability protection

Microsoft FrontPage vulnerability could allow information disclosure


Report ID: MS201309012
Date Published: 11 September 2013

Criticality: Important
Compromise Type: information-disclosure
Compromise From: remote


Affected Product/Component:

Microsoft FrontPage 2003




Summary

A vulnerability in Microsoft FrontPage could allow an attacker to disclose the contents of a file on a target system.



Detailed Description

Microsoft has released a security update to address a vulnerability in Microsoft FrontPage. The vulnerability was caused by improper parsing of the DTD of an XML file, and it could be exploited into allowing an attacker to disclose the contents of a file on a target system.

The vulnerability has been patched in the latest update by ensuring that DTD entities are properly handled. Users are recommended to install the update onto their system as a protection measure against exploit attempts.



CVE Reference

CVE-2013-3137



Solution

Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms13-078)



Security Advisories

For a list of known vulnerabilities affecting F-Secure products and the released fixes, please refer to the Security Advisories page.