CVE-2013-3889: Microsoft Excel

High severity, CVSS 9.3. EPSS: 27.4% chance of exploitation in the next 30 days.

Microsoft Excel 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office for Mac 2011; Excel Viewer; Office Compatibility Pack SP3; and Excel Services and Word Automation Services in SharePoint Server 2013 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Excel Memory Corruption Vulnerability."

Affected products

  • Microsoft Excel: version 2010 only; version 2013 only
  • Microsoft Excel Viewer: any version
  • Microsoft Office: version 2007 only; version 2010 only; version 2011 only; version 2013 only
  • Microsoft Office 2013 Rt: affected versions not specified
  • Microsoft Office Compatibility Pack: any version
  • Microsoft Office Web Apps: version 2010 only
  • Microsoft SharePoint Server: version 2007 only; version 2013 only; version 2010 only

Published 2013-10-09. Last modified 2026-06-16.