VID |
26655 |
Severity |
40 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
The hotfix (MS13-076, 2876315) for 'Vulnerability in Windows Kernel-Mode Drivers Could Allow Remote Code Execution' has not been applied. This security update resolves seven privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities.
- Multiple Win32k Multiple Fetch Vulnerabilities Elevation of privilege vulnerabilities exist when the Windows kernel-mode driver improperly handles objects in memory. An attacker who successfully exploited these vulnerabilities could gain elevated privileges and read arbitrary amounts of kernel memory.
- Win32k Elevation of Privilege Vulnerability - CVE-2013-3866 An elevation of privilege vulnerability exists when the Windows kernel-mode driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could gain elevated privileges and read arbitrary amounts of kernel memory.
* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: https://technet.microsoft.com/en-us/security/bulletin/ms13-076
* Platforms Affected: Windows XP Service Pack 3 Windows Server 2003 Service Pack 2 Windows Vista Service Pack 2 Windows Server 2008 Service Pack 2 Windows Server 2008 R2 Windows 7 SP1 Windows 8 Windows Server 2012 |
Recommendation |
Apply the appropriate patch (2876315) for your system, as listed in Microsoft Security Bulletin MS13-076 at https://technet.microsoft.com/en-us/security/bulletin/ms13-076 -- OR -- Patches for Windows platforms are also available from the Microsoft Windows Update Web site, http://windowsupdate.microsoft.com. Windows Update detects what version of Windows you are running and offers the appropriate patch. |
Related URL |
CVE-2013-1341,CVE-2013-1342,CVE-2013-1343,CVE-2013-1344,CVE-2013-3864,CVE-2013-3865,CVE-2013-3866 (CVE) |
Related URL |
62180,62193,62195,62196,62197,62198,62199 (SecurityFocus) |
Related URL |
(ISS) |
|