CVE-2013-5065
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Windows Kernel Privilege Escalation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 35% (אחוזון 100) נכון ל-24/7/2026
מוצרים מושפעים
microsoft: windows 2003 server; microsoft: windows xp
קישורים
- http://technet.microsoft.com/security/advisory/2914486 PatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-… PatchVendor Advisory
- http://technet.microsoft.com/security/advisory/2914486 PatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-… PatchVendor Advisory
- https://www.exploit-db.com/exploits/37732/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/37732/ ExploitThird Party AdvisoryVDB Entry
- http://www.fireeye.com/blog/technical/cyber-exploits/2013/11/ms-windows-local-… Broken LinkNot Applicable
- http://www.fireeye.com/blog/technical/cyber-exploits/2013/11/ms-windows-local-… Broken LinkNot Applicable
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource