CVE-2013-5065
KEVmassLocal Privilege Escalation in Microsoft Windows Kernel (NDProxy.sys)
CISA: Microsoft Windows Kernel Privilege Escalation Vulnerability
CVE-2013-5065 is a local privilege escalation flaw caused by improper input validation (CWE-20) in NDProxy.sys, a kernel driver in Microsoft Windows. A local attacker triggers the flaw by sending malformed input that reaches the vulnerable kernel driver, bypassing the usual validation checks. Successful exploitation allows the attacker to run code with elevated (kernel/SYSTEM-level) privileges, typically taking full control of the local machine from a limited-user foothold. Per CISA, Microsoft Windows is affected; no specific version ranges are provided in the source data, so defenders should consult vendor update guidance for scope. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating it is known to be exploited in the wild, though ransomware use is listed as unknown and no public PoC is catalogued.
What to do: Apply the Microsoft updates per vendor instructions as required by CISA's KEV listing, prioritizing systems that host interactive users or are entry points in your environment. Because this is a local privilege escalation, focus on limiting local/low-privileged access on Windows hosts and confirm via vendor advisories which Windows versions are in scope and patched. Treat this KEV entry as a patching priority given the confirmed in-the-wild exploitation status.
| Microsoft Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerability which can allow a local attacker to escalate privileges.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Windows
- Weakness
- CWE-20