ZeroHour
Security Affairspublished ()ingested @securityaffairs

MS Windows XP CVE-2013-5065 Eleventh zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2013-3346
Memory Corruption RCE in Adobe Reader and Acrobat

Adobe Reader and Acrobat contain a memory corruption vulnerability (CWE-119, buffer/pointer handling error) that can allow an attacker to execute arbitrary code or crash the application. The bug is triggered by processing maliciously crafted content, typically when a user opens a booby-trapped PDF document. Successful exploitation yields arbitrary code execution with the privileges of the logged-in user, while failed exploitation can cause a denial of service. Anyone running affected Adobe Reader or Acrobat installations is exposed, with desktop users who open PDFs from email or the web at greatest risk. The flaw has been exploited in the wild: CISA added it to the KEV catalog on 2022-03-03 and it carries a very high EPSS score of 78.6%, although no public proof-of-concept is known.

Do: Apply vendor-supplied updates to Adobe Reader and Acrobat immediately, per the Adobe security bulletin and the CISA KEV required action, and retire or upgrade legacy unpatched builds that are past end of support. Because exploitation requires a user to open a crafted PDF, inspect or sandbox PDFs at email and web gateways and hunt for signs of PDF exploit delivery; treat this flaw as actively exploited given the KEV listing and 78.6% EPSS.

79% KEV
  • Adobe Reader
  • Adobe Acrobat
massorder of 100M+ users at time of disclosure (Adobe Reader was then the dominant PDF reader); residual unpatched legacy deployments likely still in the millions
CVE-2013-5065
Local Privilege Escalation in Microsoft Windows Kernel (NDProxy.sys)

CVE-2013-5065 is a local privilege escalation flaw caused by improper input validation (CWE-20) in NDProxy.sys, a kernel driver in Microsoft Windows. A local attacker triggers the flaw by sending malformed input that reaches the vulnerable kernel driver, bypassing the usual validation checks. Successful exploitation allows the attacker to run code with elevated (kernel/SYSTEM-level) privileges, typically taking full control of the local machine from a limited-user foothold. Per CISA, Microsoft Windows is affected; no specific version ranges are provided in the source data, so defenders should consult vendor update guidance for scope. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating it is known to be exploited in the wild, though ransomware use is listed as unknown and no public PoC is catalogued.

Do: Apply the Microsoft updates per vendor instructions as required by CISA's KEV listing, prioritizing systems that host interactive users or are entry points in your environment. Because this is a local privilege escalation, focus on limiting local/low-privileged access on Windows hosts and confirm via vendor advisories which Windows versions are in scope and patched. Treat this KEV entry as a patching priority given the confirmed in-the-wild exploitation status.

35% KEV
  • Microsoft Windows
masswell over 1,000,000 Windows installations potentially affected (kernel driver present across Windows deployments)
Full article311 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 01, 2013

FireEye Security Experts discovered Microsoft Windows XP and Server 2003 privilege escalation zero-day exploit

Security experts at FireEye have discovered a new zero-day, a privilege escalation vulnerability in Windows XP and Windows Server 2003.

It’s is the eleventh vulnerability discovered by FireEye this year, really a great job for the researchers of the young company. The last zero-day flaw is coded by Microsoft as CVE-2013-5065, it is a privilege escalation vulnerability that is combined by hackers with another exploit in Adobe Reader (CVE-2013-3346).

Microsoft has issued a security advisory (2914486) informing the customers that Windows Kernel could allow elevation of privilege to attackers due the exploit of a bug in Windows XP’s NDPROXY.SYS driver.

“We are aware of limited, targeted attacks that attempt to exploit this vulnerability. Our investigation of this vulnerability has verified that it does not affect customers who are using operating systems newer than Windows XP and Windows Server 2003.” reported Microsoft.

Hackers could exploit the flaw to execute arbitrary code in the system’s kernel running it from a standard user account, be aware the vulnerability cannot be used for remote code execution.

“An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users” states the advisory.

The attacker once elevated his privileges is able to conduct various activities, including accessing or deleting data, installing programs or creating accounts with administrative privileges.

It must be considered that on April 10, 2012, Microsoft announced that extended support for Windows XP and Office 2003 would end on April 8, 2014 and suggested that administrators begin preparing to migrate to a newer OS. This means that XP systems will no longer receive security updates provided by Microsoft … a good reason to upgrade the OS.



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/20092/hacking/windows-xp-zero-day.html