CVE-2013-3156: Microsoft Access

High severity, CVSS 9.3. EPSS: 20% chance of exploitation in the next 30 days.

Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Access file, aka "Access File Format Memory Corruption Vulnerability."

Affected products

  • Microsoft Access: version 2007 only; version 2010 only; version 2013 only

Published 2013-09-11. Last modified 2026-06-16.