Intrusion Prevention

MS.Office.HXDS.ASLR.Bypass

Description

This indicates a attack attempt to exploit an ASLR bypass vulnerability in Microsoft Office.
The vulnerability could allow attack to bypass ASLR which helps prevent an attacker from leveraging data at predictable locations. Please note ASLR bypass by itself does not allow arbitrary code execution. However, an attacker could use this vulnerability in conjunction with another vulnerability, such as a remote code execution vulnerability that could take advantage of the ASLR bypass to run arbitrary code.

Affected Products

Microsoft Office 2007
Microsoft Office 2010

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor.
http://technet.microsoft.com/security/bulletin/MS13-106

CVE References

CVE-2013-5057