PT-2013-4712 · Microsoft · Windows+4
Published
2013-10-09
·
Updated
2018-10-12
·
CVE-2013-3880
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to the patchday that contains the fix for this issue
Windows Server 2012 versions prior to the patchday that contains the fix for this issue
Windows RT versions prior to the patchday that contains the fix for this issue
Description
The issue allows remote attackers to bypass intended access restrictions and obtain sensitive information from a different container via a Trojan horse application. It is related to an elevation of privilege vulnerability in the Windows App Container.
Recommendations
For Microsoft Windows 8, update to a version that includes the fix for this issue.
For Windows Server 2012, update to a version that includes the fix for this issue.
For Windows RT, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the App Container feature until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 8
Windows Appcontainer
Windows Rt
Windows Server 2012