#VU4790 Privilege escalation in Windows and Windows Server


Published: 2020-03-18

Vulnerability identifier: #VU4790

Vulnerability risk: Medium

CVSSv3.1:

CVE-ID: CVE-2013-3660

CWE-ID: CWE-119

Exploitation vector: Local

Exploit availability: Yes

Vulnerable software:
Windows
Operating systems & Components / Operating system
Windows Server
Operating systems & Components / Operating system

Vendor: Microsoft

Description
The vulnerability allows a local attacker to obtain elevated privileges on the target system.

The weakness exists due to the failure to properly initialize a pointer for the next object in a certain list by the EPATHOBJ::pprFlattenRec function within kernel-mode driver (win32k.sys). A local attacker can use multiple FlattenPath function calls to obtain write access to the PATHRECORD chain and execute arbitrary code on the system with elevated privileges.

Successful exploitation of the vulnerability results in arbitrary code execution on the vulnerable system.

Note: the vulnerability was being actively exploited.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Windows: XP, 8, 7, Vista

Windows Server: 2003 - 2012


CPE

External links
http://technet.microsoft.com/en-us/library/security/ms13-053


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?


Latest bulletins with this vulnerability