Microsoft Office Publisher Remote Code Execution Vulnerability (2830397)

Summary
This host is missing an important security update according to Microsoft Bulletin MS13-042.
Impact
Successful exploitation could allow attackers to execute arbitrary code by tricking a user into opening a specially crafted publisher files. Impact Level: System/Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/ms13-042
Insight
Multiple flaws are due to, - An unspecified errors when handling array size, return values, table range data, NULL values. - An integer overflow vulnerability exists. - A signedness error exists when parsing certain data, which can be exploited to corrupt memory.
Affected
Microsoft Publisher 2003 Service Pack 3 and prior Microsoft Publisher 2007 Service Pack 3 and prior Microsoft Publisher 2010 Service Pack 1 and prior
References