PT-2013-1050 · Microsoft · Windows Xp+2
Tomislav Paskalev
·
Publicado
2013-11-27
·
Atualizado
2025-04-04
·
CVE-2013-5065
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows XP versions SP2 through SP3
Microsoft Windows Server 2003 version SP2
Description
The issue exists in the NDProxy component of the Windows kernel due to improper validation of input passed from user mode to the kernel. This allows an attacker to run code in kernel mode, potentially giving them complete control over the system. The attacker could then install programs, view, change, or delete data, or create new accounts with full administrator rights. The vulnerability has been exploited in the wild.
Recommendations
For Microsoft Windows XP versions SP2 through SP3, consider applying security updates to address the issue.
For Microsoft Windows Server 2003 version SP2, apply the relevant security patch to mitigate the risk of exploitation.
As a temporary workaround, consider restricting access to the NDProxy component until a patch is applied.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Windows
Windows Server 2003
Windows Xp