Sploitus

CVE-2013-3660

8 known exploits for CVE-2013-3660

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."

Microsoft Windows 7
All versions
Microsoft Windows 8
All versions
Microsoft Windows Rt
All versions
Microsoft Windows Server 2003
All versions
Microsoft Windows Server 2008
All versions
Microsoft Windows Server 2012
All versions
Fix
Available
CVSS 3.1
7.8 HIGH
EPSS
39.6% (99th percentile)
Weakness
CWE-119
NVD status
Analyzed
Published
2013-05-24
CVE-2013-3660 at NVD
Authoritative description, scoring and affected products

8 known exploits for CVE-2013-3660

Proof-of-concept code and exploit modules indexed by Sploitus