Lucene search

K
cve[email protected]CVE-2013-0008
HistoryJan 09, 2013 - 6:09 p.m.

CVE-2013-0008

2013-01-0918:09:40
CWE-264
web.nvd.nist.gov
37
cve-2013-0008
win32k
improper message handling
vulnerability
windows vista
windows server
privilege escalation
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.2 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

34.0%

win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle window broadcast messages, which allows local users to gain privileges via a crafted application, aka “Win32k Improper Message Handling Vulnerability.”

Affected configurations

NVD
Node
microsoftwindows_vistasp2
Node
microsoftwindows_server_2008sp2x64
OR
microsoftwindows_server_2008sp2x86
OR
microsoftwindows_server_2008Match-sp2itanium
Node
microsoftwindows_7x64
OR
microsoftwindows_7x86
OR
microsoftwindows_7sp1x86
OR
microsoftwindows_7Match-sp1x64
Node
microsoftwindows_server_2008Matchr2itanium
OR
microsoftwindows_server_2008Matchr2x64
Node
microsoftwindows_8Match--x64
OR
microsoftwindows_8Match--x86
Node
microsoftwindows_server_2012Match-
Node
microsoftwindows_rtMatch-

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.2 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

34.0%