Vulnerability Name: | CVE-2013-3887 (CCN-88367) | ||||||||
Assigned: | 2013-11-12 | ||||||||
Published: | 2013-11-12 | ||||||||
Updated: | 2020-09-28 | ||||||||
Summary: | The Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows local users to obtain sensitive information from kernel memory by leveraging improper copy operations, aka "Ancillary Function Driver Information Disclosure Vulnerability." | ||||||||
CVSS v3 Severity: | 2.8 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N/E:U/RL:OF/RC:C)
1.3 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-3887 Source: CCN Type: SA55558 Microsoft Windows Ancillary Function Driver Information Disclosure Weakness Source: CCN Type: Microsoft Security Bulletin MS13-093 Vulnerability in Windows Ancillary Function Driver Could Allow Information Disclosure (2875783) Source: CCN Type: Microsoft Security Bulletin MS14-040 Vulnerability in Ancillary Function Driver (AFD) Could Allow Elevation of Privilege (2975684) Source: CCN Type: Microsoft Security Bulletin MS15-119 Security Update in Winsock to Address Elevation of Privilege (3104521) Source: CCN Type: BID-63545 Microsoft Windows Ancillary Function Driver CVE-2013-3887 Local Information Disclosure Vulnerability Source: CERT Type: US Government Resource TA13-317A Source: MS Type: UNKNOWN MS13-093 Source: XF Type: UNKNOWN ms-afd-cve20133887-info-disc(88367) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:18805 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |