Lucene search

K
cve[email protected]CVE-2013-3887
HistoryNov 13, 2013 - 12:55 a.m.

CVE-2013-3887

2013-11-1300:55:02
CWE-200
web.nvd.nist.gov
25
ancillary function driver
afd
microsoft
windows
information disclosure
vulnerability
kernel memory
nvd
cve-2013-3887

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:C/I:N/A:N

5.4 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.2%

The Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows local users to obtain sensitive information from kernel memory by leveraging improper copy operations, aka “Ancillary Function Driver Information Disclosure Vulnerability.”

Affected configurations

NVD
Node
microsoftwindows_7sp1x64
OR
microsoftwindows_8Match--x64
OR
microsoftwindows_server_2003sp2
OR
microsoftwindows_server_2008sp2itanium
OR
microsoftwindows_server_2008sp2x64
OR
microsoftwindows_server_2012Match-
OR
microsoftwindows_vistasp2
OR
microsoftwindows_xpMatch-sp2x64

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:C/I:N/A:N

5.4 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.2%