PT-2013-1050 · Microsoft · Windows Xp+2

Tomislav Paskalev

·

Publicado

2013-11-27

·

Atualizado

2025-04-04

·

CVE-2013-5065

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows XP versions SP2 through SP3 Microsoft Windows Server 2003 version SP2
Description The issue exists in the NDProxy component of the Windows kernel due to improper validation of input passed from user mode to the kernel. This allows an attacker to run code in kernel mode, potentially giving them complete control over the system. The attacker could then install programs, view, change, or delete data, or create new accounts with full administrator rights. The vulnerability has been exploited in the wild.
Recommendations For Microsoft Windows XP versions SP2 through SP3, consider applying security updates to address the issue. For Microsoft Windows Server 2003 version SP2, apply the relevant security patch to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to the NDProxy component until a patch is applied.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-00744
CVE-2013-5065

Produtos afetados

Windows
Windows Server 2003
Windows Xp