CVE-2013-1339
The Print Spooler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly manage memory during deletion of printer connections, which allows remote authenticated…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 23.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The Print Spooler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly manage memory during deletion of printer connections, which allows remote authenticated users to execute arbitrary code via a crafted request, aka "Print Spooler Vulnerability."
- CVSS 2.0
- 9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 23.63% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- microsoft/windows 7 · microsoft/windows 8 · microsoft/windows rt · microsoft/windows server 2008 · microsoft/windows server 2012 · microsoft/windows vista
- Source
- secure@microsoft.com
References
- http://www.us-cert.gov/ncas/alerts/TA13-168AUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-050
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16837
- http://www.us-cert.gov/ncas/alerts/TA13-168AUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-050
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16837
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.