ZeroHour

CVE-2013-5065

KEVmass

Local Privilege Escalation in Microsoft Windows Kernel (NDProxy.sys)

CISA: Microsoft Windows Kernel Privilege Escalation Vulnerability

CVSS
EPSS
35%p98
Published
KEV added
AI analysis

CVE-2013-5065 is a local privilege escalation flaw caused by improper input validation (CWE-20) in NDProxy.sys, a kernel driver in Microsoft Windows. A local attacker triggers the flaw by sending malformed input that reaches the vulnerable kernel driver, bypassing the usual validation checks. Successful exploitation allows the attacker to run code with elevated (kernel/SYSTEM-level) privileges, typically taking full control of the local machine from a limited-user foothold. Per CISA, Microsoft Windows is affected; no specific version ranges are provided in the source data, so defenders should consult vendor update guidance for scope. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating it is known to be exploited in the wild, though ransomware use is listed as unknown and no public PoC is catalogued.

What to do: Apply the Microsoft updates per vendor instructions as required by CISA's KEV listing, prioritizing systems that host interactive users or are entry points in your environment. Because this is a local privilege escalation, focus on limiting local/low-privileged access on Windows hosts and confirm via vendor advisories which Windows versions are in scope and patched. Treat this KEV entry as a patching priority given the confirmed in-the-wild exploitation status.

Affected
Microsoft Windows
Estimated exposure
masswell over 1,000,000 Windows installations potentially affected (kernel driver present across Windows deployments) — Microsoft Windows runs on over a billion devices worldwide, and a local kernel privilege escalation in a core driver potentially applies to any deployment running affected Windows versions, making the plausible exposure at least millions…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerability which can allow a local attacker to escalate privileges.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Windows
Weakness
CWE-20

In the news