Vulnerability CVE-2013-1283

See in [MITRE] [NVD]

Search:
WLB2

Vulnerability CVE-2013-1283


Published: 2013-04-09   Modified: 2013-04-10

Description:
Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."

Vendor: Microsoft
Product: Windows server 2008 
Version: r2;
Product: Windows 7 
Product: Windows server 2003 
Product: Windows vista 
Product: Windows xp 
Product: Windows 8 
Product: Windows rt 
Product: Windows server 2012 

CVSS2 => (AV:L/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.9/10
10/10
3.4/10
Exploit range
Attack complexity
Authentication
Local
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

Related CVE
[ CVE-2014-6324 ]
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vi...
[ CVE-2014-8442 ]
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS ...
[ CVE-2014-8441 ]
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS ...
[ CVE-2014-8440 ]
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS ...
[ CVE-2014-6353 ]
Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code ...
[ CVE-2014-6351 ]
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code ...
[ CVE-2014-6350 ]
Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a craf...
[ CVE-2014-6349 ]
Microsoft Internet Explorer 10 and 11 allows remote attackers to gain privileges via a craf...
[ CVE-2014-6348 ]
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a ...
[ CVE-2014-6347 ]
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a...

References:
http://technet.microsoft.com/security/bulletin/MS13-036
Copyright 2014, cxsecurity.com