Vulnerability Name: | CVE-2013-2556 (CCN-82772) | ||||||||
Assigned: | 2013-03-02 | ||||||||
Published: | 2013-03-02 | ||||||||
Updated: | 2020-09-28 | ||||||||
Summary: | Unspecified vulnerability in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 through SP1 allows attackers to bypass the ASLR protection mechanism via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "ASLR Security Feature Bypass Vulnerability." | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-2556 Source: CCN Type: HP Communities Web site Pwn2Own 2013 Source: MISC Type: UNKNOWN http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157 Source: CCN Type: Microsoft Security Bulletin MS13-063 Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2859537) Source: CCN Type: Microsoft Security Bulletin MS13-077 Vulnerability in Windows Service Control Manager Could Allow Elevation of Privilege (2872339) Source: MISC Type: UNKNOWN http://twitter.com/thezdi/statuses/309756927301283840 Source: MISC Type: UNKNOWN http://twitter.com/VUPEN/statuses/309713355466227713 Source: CCN Type: Microsoft Web site Windows 7 Source: CCN Type: BID-58566 Microsoft Windows CVE-2013-2556 ASLR Security Bypass Vulnerability Source: CERT Type: US Government Resource TA13-225A Source: MS Type: UNKNOWN MS13-063 Source: XF Type: UNKNOWN ms-win-aslr-sec-bypass(82772) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:18132 Source: CCN Type: ZDI-13-192 (Pwn2Own) Microsoft Windows Shared Data ASLR Security Feature Bypass Vulnerability | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |