VulnerabilityAnalyzed
CVE-2013-5065
Microsoft Windows Kernel Privilege Escalation Vulnerability
KEVHIGH 7.8EPSS 34.9%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 34.89% probability · 98th percentile
- CISA KEV
- Listed 3 March 2022 · due 24 March 2022
- Affected
- microsoft/windows 2003 server · microsoft/windows xp
- Source
- secure@microsoft.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2013-5065
References
- http://technet.microsoft.com/security/advisory/2914486Patch, Vendor Advisory
- http://www.fireeye.com/blog/technical/cyber-exploits/2013/11/ms-windows-local-privilege-escalation-zero-day-in-the-wild.htmlBroken Link, Not Applicable
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-002Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/37732/Exploit, Third Party Advisory, VDB Entry
- http://technet.microsoft.com/security/advisory/2914486Patch, Vendor Advisory
- http://www.fireeye.com/blog/technical/cyber-exploits/2013/11/ms-windows-local-privilege-escalation-zero-day-in-the-wild.htmlBroken Link, Not Applicable
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-002Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/37732/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-5065US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.