CVE-2013-3154: Medium severity Microsoft Windows Defender vulnerability
The signature-update functionality in Windows Defender on Microsoft Windows 7 and Windows Server 2008 R2 relies on an incorrect pathname, which allows local users to gain privileges via a Trojan horse application in the %SYSTEMDRIVE% top-level directory, aka "Microsoft Windows 7 Defender Improper Pathname Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3154?
CVE-2013-3154 has a medium severity rating due to its potential for privilege escalation.
How do I fix CVE-2013-3154?
To mitigate CVE-2013-3154, ensure that you apply the latest security updates provided by Microsoft for Windows 7 and Windows Server 2008 R2.
Which versions are affected by CVE-2013-3154?
CVE-2013-3154 affects Microsoft Windows 7 and Microsoft Windows Server 2008 R2.
Can local users exploit CVE-2013-3154?
Yes, local users can exploit CVE-2013-3154 through a Trojan horse application due to improper pathname handling.
What component of Windows is impacted by CVE-2013-3154?
The vulnerability affects the signature-update functionality of Windows Defender in the specified Windows operating systems.