Microsoft released security bulletin MS13-002 to fix two privately reported remote code execution vulnerabilities in Microsoft XML Core Services (MSXML), tracked as CVE-2013-0006 and CVE-2013-0007. The flaws could be triggered if a user visited a specially crafted webpage in Internet Explorer, allowing an attacker to run arbitrary code with the privileges of the logged-on user. Microsoft rated the issue Critical for affected client platforms and for MSXML 5.0 components shipped with several Microsoft Office and server products, while most affected Windows Server systems were rated Moderate because of lower exposure.
The update changes how MSXML parses XML content and Microsoft urged organizations to deploy it promptly through automatic updating or Microsoft Update. The company also said update KB2687497 for SharePoint Server 2007 and Groove Server 2007 was rereleased as a new package and must be installed again even if the earlier MS12-043 version was already present. Microsoft said the vulnerabilities had not been publicly disclosed and there was no evidence of active exploitation when the bulletin was originally issued.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
On December 16, 2013, Microsoft updated MS13-002 and stated that KB2687497 for SharePoint Server 2007 and Groove Server 2007 had been rereleased as a new package. Microsoft instructed customers to install the new package even if the original MS12-043 version was already installed.
On January 8, 2013, Microsoft published Security Bulletin MS13-002 to address the privately reported vulnerabilities CVE-2013-0006 and CVE-2013-0007 in Microsoft XML Core Services. Microsoft said the flaws could allow remote code execution if a user visited a specially crafted webpage in Internet Explorer and noted there was no public disclosure or active exploitation at the time of release.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 150 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
support.microsoft.com
Open sourcesupport.microsoft.com
Open sourcesupport.microsoft.com
Open sourcesupport.microsoft.com
Open sourcesupport.microsoft.com
Open sourcetechnet.microsoft.com
Open sourcetechnet.microsoft.com
Open sourcego.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.