CVE-2013-0007: Microsoft Expression Web
High severity, CVSS 9.3. EPSS: 31.6% chance of exploitation in the next 30 days.
Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML XSLT Vulnerability."
Affected products
- Microsoft Expression Web: any version; version 2 only
- Microsoft Groove Server: version 2007 only
- Microsoft Office: version 2003 only; version 2007 only
- Microsoft Office Compatibility Pack: any version
- Microsoft SharePoint Server: version 2007 only
- Microsoft Windows 7: affected versions not specified
- Microsoft Windows 8: affected versions not specified
- Microsoft Windows Rt: affected versions not specified
- Microsoft Windows Server 2003: any version
- Microsoft Windows Server 2008: affected versions not specified; version r2 only; any version
- Microsoft Windows Server 2012: affected versions not specified
- Microsoft Windows Vista: any version
- Microsoft Windows XP: affected versions not specified; any version
- Microsoft Word Viewer: any version
- Microsoft XML Core Services: version 3.0 only; version 4.0 only; version 6.0 only; version 5.0 only
Published 2013-01-09. Last modified 2026-06-16.