Vulnerability Name: CVE-2013-1286 (CCN-82413) Assigned: 2013-03-12 Published: 2013-03-12 Updated: 2020-09-28 Summary: The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285  and CVE-2013-1287 . CVSS v3 Severity: 9.3 Critical  (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H  )Exploitability Metrics: Attack Vector (AV):  LocalAttack Complexity (AC):  LowPrivileges Required (PR):  NoneUser Interaction (UI):  NoneScope: Scope (S):  ChangedImpact Metrics: Confidentiality (C):  HighIntegrity (I):  HighAvailibility (A):  High
CVSS v2 Severity: 7.2 High  (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C  )5.3 Medium  (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C  )Exploitability Metrics: Access Vector (AV):  LocalAccess Complexity (AC):  LowAuthentication (Au):  NoneImpact Metrics: Confidentiality (C):  CompleteIntegrity (I):  CompleteAvailibility (A):  Complete
7.2 High  (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C  )5.3 Medium  (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C  )Exploitability Metrics: Access Vector (AV):  LocalAccess Complexity (AC):  LowAthentication (Au):  NoneImpact Metrics: Confidentiality (C):  CompleteIntegrity (I):  CompleteAvailibility (A):  Complete
Vulnerability Type: CWE-264 Vulnerability Consequences: Gain Privileges References: Source: MITRE Type: CNACVE-2013-1286  Source: CCN Type: SA52561Microsoft Windows Kernel-Mode Driver USB Descriptor Vulnerabilities  Source: CCN Type: Microsoft Security Bulletin MS13-027Vulnerabilities in Kernel-Mode Driver Could Allow Elevation Of Privilege (2807986)  Source: CCN Type: BID-58360Microsoft Windows CVE-2013-1286 Local Privilege Escalation Vulnerability  Source: CERT Type: US Government ResourceTA13-071A  Source: MS Type: UNKNOWNMS13-027  Source: XF Type: UNKNOWNms-windows-usb-priv-esc(82413)  Source: OVAL Type: UNKNOWNoval:org.mitre.oval:def:16591  Vulnerable Configuration: Configuration 1 :cpe:/o:microsoft:windows_xp:*:sp3:*:*:*:*:*:* OR cpe:/o:microsoft:windows_xp:-:sp2:x64:*:*:*:*:*  Configuration 2 :cpe:/o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:* Configuration 3 :cpe:/o:microsoft:windows_vista:*:sp2:x64:*:*:*:*:* OR cpe:/o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*  Configuration 4 :cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x64:* OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:x32:*  OR cpe:/o:microsoft:windows_server_2008:-:sp2:itanium:*:*:*:*:*  Configuration 5 :cpe:/o:microsoft:windows_7:-:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_7:-:sp1:*:*:ultimate_n:*:x64:*  OR cpe:/o:microsoft:windows_7:-:sp1:*:*:ultimate_n:*:x86:*  Configuration 6 :cpe:/o:microsoft:windows_server_2008:*:r2:itanium:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2008:*:r2:x64:*:*:*:*:*  Configuration 7 :cpe:/o:microsoft:windows_8:-:*:*:*:pro_n:*:x64:* OR cpe:/o:microsoft:windows_8:-:*:*:*:pro_n:*:x86:*  Configuration 8 :cpe:/o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/o:microsoft:windows:server_2003:sp2:*:*:*:*:*:* OR cpe:/o:microsoft:windows:server_2003:sp2:itanium:*:*:*:*:*  OR cpe:/o:microsoft:windows:server_2003:sp2:x64:*:*:*:*:*  OR cpe:/o:microsoft:windows_xp::sp2:x64:*:professional:*:*:*  OR cpe:/o:microsoft:windows_server_2008:*:*:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows:xp:sp3:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_vista:-:sp2:x64:*:*:*:*:*  OR cpe:/o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x32:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_7:-:*:*:*:*:*:x32:*  OR cpe:/o:microsoft:windows_server_2008:r2:*:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:r2:*:*:*:*:*:itanium:*  OR cpe:/o:microsoft:windows_server_2008:*:sp2:*:*:*:*:itanium:*  OR cpe:/o:microsoft:windows_7:-:sp1:*:*:ultimate_n:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*  OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*    Denotes that component is vulnerable  Oval Definitions Definition ID Class Title Last Modified oval:org.mitre.oval:def:16591 V Microsoft kernel-mode drivers privilege elevation vulnerability (CVE-2013-1286) - MS13-027 2014-03-03 
  BACK   
  microsoft  windows xp * sp3    
microsoft  windows xp - sp2    
microsoft  windows server 2003 * sp2    
microsoft  windows vista * sp2    
microsoft  windows vista - sp2    
microsoft  windows server 2008 * sp2    
microsoft  windows server 2008 * sp2    
microsoft  windows server 2008 - sp2    
microsoft  windows 7 -    
microsoft  windows 7 - sp1    
microsoft  windows 7 - sp1    
microsoft  windows server 2008 * r2    
microsoft  windows server 2008 * r2    
microsoft  windows 8 - -    
microsoft  windows 8 - -    
microsoft  windows server 2012 -    
microsoft  windows server_2003 sp2    
microsoft  windows server_2003 sp2    
microsoft  windows server_2003 sp2    
microsoft  windows xp  sp2    
microsoft  windows server 2008 -    
microsoft  windows xp sp3    
microsoft  windows vista - sp2    
microsoft  windows vista - sp2    
microsoft  windows server 2008 sp2    
microsoft  windows server 2008 sp2    
microsoft  windows 7 - 
microsoft  windows server 2008 - r2    
microsoft  windows server 2008  r2    
microsoft  windows server 2008     
microsoft  windows 7 - sp1    
microsoft  windows server 2008 r2 sp1    
microsoft  windows server 2008 r2 sp1