CVE-2013-0078: Input Validation
The Microsoft Antimalware Client in Windows Defender on Windows 8 and Windows RT uses an incorrect pathname for MsMpEng.exe, which allows local users to gain privileges via a crafted application, aka "Microsoft Antimalware Improper Pathname Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0078?
CVE-2013-0078 has a moderate severity rating due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-2013-0078?
To fix CVE-2013-0078, ensure that you install the latest security updates provided by Microsoft for Windows Defender.
What versions of Windows are affected by CVE-2013-0078?
CVE-2013-0078 affects Microsoft Windows Defender on Windows 8 and Windows RT.
What is the nature of the vulnerability in CVE-2013-0078?
The vulnerability in CVE-2013-0078 is caused by an improper pathname for MsMpEng.exe in Microsoft Antimalware Client.
Can exploiting CVE-2013-0078 be mitigated?
Exploitation of CVE-2013-0078 can be mitigated by restricting local user access and applying the necessary security updates.