PT-2013-6224 · Microsoft · Windows Server 2008 R2

Sixtyvividtails

·

Publicado

2013-12-07

·

Atualizado

2024-08-06

·

CVE-2013-6999

CVSS v2.0

4.0

Média

VetorAV:L/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows Server 2008 SP2
Description The IsHandleEntrySecure function in win32k.sys does not properly validate the tagPROCESSINFO pW32Job field, allowing local users to cause a denial of service via a crafted NtUserValidateHandleSecure call for an owned object. This can result in a NULL pointer dereference and system crash. The vendor reportedly disputes the significance of this report, considering it a local denial of service rather than a security vulnerability.
Recommendations For Microsoft Windows Server 2008 SP2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2013-6999

Produtos afetados

Windows Server 2008 R2