Microsoft · Windows Server 2012 · CVE-2013-1300
**Name of the Vulnerable Software and Affected Versions**
Microsoft Windows XP versions SP2 and SP3
Microsoft Windows Server 2003 version SP2
Microsoft Windows Vista version SP2
Microsoft Windows Server 2008 versions SP2 and R2 SP1
Microsoft Windows 7 version SP1
Microsoft Windows 8
Microsoft Windows Server 2012
Microsoft Windows RT
**Description**
The issue arises from improper handling of objects in memory by the Windows kernel-mode driver, allowing local users to gain privileges via a crafted application. An attacker who successfully exploits this could execute arbitrary code with elevated privileges.
**Recommendations**
For Microsoft Windows XP versions SP2 and SP3, update to a newer version to mitigate the risk.
For Microsoft Windows Server 2003 version SP2, update to a newer version to mitigate the risk.
For Microsoft Windows Vista version SP2, update to a newer version to mitigate the risk.
For Microsoft Windows Server 2008 versions SP2 and R2 SP1, update to a newer version to mitigate the risk.
For Microsoft Windows 7 version SP1, update to a newer version to mitigate the risk.
For Microsoft Windows 8, update to a newer version to mitigate the risk.
For Microsoft Windows Server 2012, update to a newer version to mitigate the risk.
For Microsoft Windows RT, update to a newer version to mitigate the risk.