CVE-2013-1313: Microsoft Windows XP

High severity, CVSS 9.3. EPSS: 22.7% chance of exploitation in the next 30 days.

Object Linking and Embedding (OLE) Automation in Microsoft Windows XP SP3 does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted RTF document, aka "OLE Automation Remote Code Execution Vulnerability."

Affected products

Published 2013-02-13. Last modified 2026-06-16.