SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2013-5065

Microsoft Windows Kernel Privilege Escalation Vulnerability

KEVHIGH 7.8EPSS 34.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
34.89% probability · 98th percentile
CISA KEV
Listed 3 March 2022 · due 24 March 2022
Affected
microsoft/windows 2003 server · microsoft/windows xp
Source
secure@microsoft.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2013-5065

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.