PT-2013-4553 · Microsoft · Windows Server 2012+8

Publicado

2013-05-24

·

Atualizado

2025-04-03

·

CVE-2013-3660

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows XP versions SP2 and SP3 Microsoft Windows Server 2003 version SP2 Microsoft Windows Vista version SP2 Microsoft Windows Server 2008 versions SP2 and R2 SP1 Microsoft Windows 7 version SP1 Microsoft Windows 8 Microsoft Windows Server 2012
Description The issue arises from the improper initialization of a pointer for the next object in a certain list by the EPATHOBJ::pprFlattenRec function in win32k.sys. This allows local users to gain privileges by obtaining write access to the PATHRECORD chain, which can be achieved by triggering excessive consumption of paged memory and then making many FlattenPath function calls. Although a theoretical remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles objects in memory, the remote attack vector is not likely, and an attacker would probably need to log on to the target system to exploit this issue and gain elevated privileges.
Recommendations For Microsoft Windows XP versions SP2 and SP3, update to a newer version to mitigate the risk. For Microsoft Windows Server 2003 version SP2, update to a newer version to mitigate the risk. For Microsoft Windows Vista version SP2, update to a newer version to mitigate the risk. For Microsoft Windows Server 2008 versions SP2 and R2 SP1, update to a newer version to mitigate the risk. For Microsoft Windows 7 version SP1, update to a newer version to mitigate the risk. For Microsoft Windows 8, update to a newer version to mitigate the risk. For Microsoft Windows Server 2012, update to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to the win32k.sys driver to minimize the risk of exploitation.

Exploit

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-3660

Produtos afetados

Windows
Windows 7
Windows 8
Windows Server 2003
Windows Server 2008
Windows Server 2012
Windows Vista
Windows Xp
Win32K.Sys