Vulnerability Name: | CVE-2013-3878 (CCN-89309) | ||||||||
Assigned: | 2013-12-10 | ||||||||
Published: | 2013-12-10 | ||||||||
Updated: | 2019-02-26 | ||||||||
Summary: | Stack-based buffer overflow in the LRPC client in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges by operating an LRPC server that sends a crafted LPC port message, aka "LRPC Client Buffer Overrun Vulnerability." | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C) 5.1 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-3878 Source: CCN Type: SA55988 Microsoft Windows LRPC Client Buffer Overflow Vulnerability Source: CCN Type: Microsoft Security Bulletin MS13-102 Vulnerability in Windows Local Procedure Call Could Allow Elevation of Privilege (2898715) Source: CCN Type: BID-64088 Microsoft Windows Local Procedure Call CVE-2013-3878 Local Privilege Escalation Vulnerability Source: MS Type: UNKNOWN MS13-102 Source: XF Type: UNKNOWN ms-win-lpc-cve20133878-priv-esc(89309) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |