CVE-2013-3200: Code Injection
The USB drivers in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allow physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3200?
The severity of CVE-2013-3200 is classified as critical due to the potential for arbitrary code execution by local attackers.
How do I fix CVE-2013-3200?
To fix CVE-2013-3200, apply the security updates provided by Microsoft for your affected Windows version.
Which Windows versions are affected by CVE-2013-3200?
CVE-2013-3200 affects Windows XP, Windows Vista, Windows 7, Windows 8, various Windows Server versions, and Windows RT with specific service pack requirements.
What type of attack does CVE-2013-3200 enable?
CVE-2013-3200 enables physically proximate attackers to execute arbitrary code by connecting specially crafted USB devices.
Is there a workaround for CVE-2013-3200?
There is no specific workaround for CVE-2013-3200; the recommended action is to apply the relevant patches from Microsoft.