Oval Definition:oval:org.mitre.oval:def:26382
Revision Date:2014-10-13Version:44
Title:Service Control Manager Double Free Vulnerability (MS13-077)
Description:Double free vulnerability in Microsoft Windows 7 and Server 2008 R2 SP1 allows local users to gain privileges via a crafted service description that is not properly handled by services.exe in the Service Control Manager (SCM), aka "Service Control Manager Double Free Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2013-3862
Platform(s):Microsoft Windows 7
Microsoft Windows Server 2008 R2
Product(s):
Definition Synopsis
  • OS section
  • Microsoft Windows 7 (32-bit) Service Pack 1 is installed
  • OR Microsoft Windows 7 x64 Service Pack 1 is installed
  • OR Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed
  • OR Microsoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed
  • AND GDR/LDR
  • Check if the version of winsrv.dll is less than 6.1.7601.18229
  • OR LDR range
  • Check if the version of winsrv.dll is less than 6.1.7601.22411
  • AND the version of Winsrv.dll is greater than or equal to 6.1.7601.21000
  • BACK