CVE-2013-0008
win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle window broadcast messages, which allows local…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 17.1%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle window broadcast messages, which allows local users to gain privileges via a crafted application, aka "Win32k Improper Message Handling Vulnerability."
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 17.09% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- microsoft/windows vista · microsoft/windows server 2008 · microsoft/windows 7 · microsoft/windows 8 · microsoft/windows server 2012 · microsoft/windows rt
- Source
- secure@microsoft.com
References
- http://www.exploit-db.com/exploits/24485
- http://www.securityfocus.com/bid/57135
- http://www.us-cert.gov/cas/techalerts/TA13-008A.htmlUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-005
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16326
- http://www.exploit-db.com/exploits/24485
- http://www.securityfocus.com/bid/57135
- http://www.us-cert.gov/cas/techalerts/TA13-008A.htmlUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-005
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16326
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.