Vulnerability Name: CVE-2013-1274 (CCN-81662) Assigned: 2013-02-12 Published: 2013-02-12 Updated: 2020-09-28 Summary: Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016. CVSS v3 Severity: 9.3 Critical  (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Exploitability Metrics: Attack Vector (AV):  LocalAttack Complexity (AC):  LowPrivileges Required (PR):  NoneUser Interaction (UI):  NoneScope: Scope (S):  ChangedImpact Metrics: Confidentiality (C):  HighIntegrity (I):  HighAvailibility (A):  High
CVSS v2 Severity: 4.9 Medium  (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N 3.7 Low  (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N/E:U/RL:OF/RC:C Exploitability Metrics: Access Vector (AV):  LocalAccess Complexity (AC):  LowAuthentication (Au):  NoneImpact Metrics: Confidentiality (C):  CompleteIntegrity (I):  NoneAvailibility (A):  None
7.2 High  (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C 5.3 Medium  (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C Exploitability Metrics: Access Vector (AV):  LocalAccess Complexity (AC):  LowAthentication (Au):  NoneImpact Metrics: Confidentiality (C):  CompleteIntegrity (I):  CompleteAvailibility (A):  Complete
Vulnerability Type: CWE-362 Vulnerability Consequences: Gain Privileges References: Source: MITRECVE-2013-1274 Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2778344) Vulnerabilities in Kernel-Mode Driver Could Allow Elevation Of Privilege (2829996) Vulnerabilities in Kernel-Mode Drivers Could Allow Elevation Of Privilege (2840221) Vulnerability in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2850851) Vulnerabilities in Kernel-Mode Drivers Could Allow Elevation of Privilege (2880407) Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (2870008) Microsoft Windows 'Win32k.sys' CVE-2013-1274 Local Privilege Escalation Vulnerability TA13-043B MS13-016 ms-win-cve20131274-priv-esc(81662) oval:org.mitre.oval:def:16224  Vulnerable Configuration: Configuration 1 :cpe:/o:microsoft:windows_7:*:*:x64:*:*:*:*:* OR cpe:/o:microsoft:windows_7:*:*:x86:*:*:*:*:*  OR cpe:/o:microsoft:windows_7:*:sp1:x64:*:*:*:*:*  OR cpe:/o:microsoft:windows_7:*:sp1:x86:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:*:r2:itanium:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:*:r2:x64:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:itanium:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:x32:*  OR cpe:/o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_vista:*:sp2:x64:*:*:*:*:*  OR cpe:/o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_xp:-:sp2:x64:*:*:*:*:*  Configuration CCN 1 :cpe:/o:microsoft:windows_xp::sp2:x64:*:professional:*:*:* OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_vista:-:sp2:x64:*:*:*:*:*  OR cpe:/o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x32:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_7:-:-:*:*:ultimate_n:*:x64:*  OR cpe:/o:microsoft:windows_7:-:*:*:*:*:*:x32:*  OR cpe:/o:microsoft:windows_server_2008:r2:*:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:r2:*:*:*:*:*:itanium:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:itanium:*  OR cpe:/o:microsoft:windows:2003_server:sp2_itanium:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_7:-:sp1:-:*:-:-:x32:*  OR cpe:/o:microsoft:windows_7:-:sp1:*:*:ultimate_n:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*  OR cpe:/o:microsoft:windows:2003_server:sp2_x64:*:*:*:*:*:*  OR cpe:/o:microsoft:windows:xp:sp3:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_8:-:-:-:*:-:-:x32:*  OR cpe:/o:microsoft:windows_8:-:-:-:*:-:-:x64:*  OR cpe:/o:microsoft:windows_server_2012:*:*:*:*:*:*:*:*  Oval Definitions BACK 
microsoft  windows 7 *    
microsoft  windows 7 *    
microsoft  windows 7 * sp1    
microsoft  windows 7 * sp1    
microsoft  windows server 2003 * sp2    
microsoft  windows server 2008 * r2    
microsoft  windows server 2008 * r2    
microsoft  windows server 2008 * sp2    
microsoft  windows server 2008 * sp2    
microsoft  windows server 2008 * sp2    
microsoft  windows vista * sp2    
microsoft  windows vista * sp2    
microsoft  windows xp * sp3    
microsoft  windows xp - sp2    
microsoft  windows xp  sp2    
microsoft  windows server 2008 -    
microsoft  windows vista - sp2    
microsoft  windows vista - sp2    
microsoft  windows server 2008 sp2    
microsoft  windows server 2008 sp2    
microsoft  windows 7 - 
microsoft  windows 7 - 
microsoft  windows server 2008 - r2    
microsoft  windows server 2008  r2    
microsoft  windows server 2008     
microsoft  windows 2003_server sp2_itanium    
microsoft  windows 7 - sp1    
microsoft  windows 7 - sp1    
microsoft  windows server 2008 r2 sp1    
microsoft  windows server 2008 r2 sp1    
microsoft  windows 2003_server sp2_x64    
microsoft  windows xp sp3    
microsoft  windows 8 - -    
microsoft  windows 8 - -    
microsoft  windows server 2012