First published: Wed Sep 11 2013(Updated: )
Double free vulnerability in Microsoft Windows 7 and Server 2008 R2 SP1 allows local users to gain privileges via a crafted service description that is not properly handled by services.exe in the Service Control Manager (SCM), aka "Service Control Manager Double Free Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows Server | =r2 | |
Microsoft Windows Server | =r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3862 is rated as a critical vulnerability due to its potential to allow local users to gain elevated privileges.
To fix CVE-2013-3862, apply the latest security updates released by Microsoft for affected versions of Windows 7 and Windows Server 2008 R2.
CVE-2013-3862 affects local users of Microsoft Windows 7 and Windows Server 2008 R2 SP1 who can exploit the vulnerability.
CVE-2013-3862 is a double free vulnerability that occurs in the Service Control Manager (SCM) in affected versions of Windows.
Exploiting CVE-2013-3862 allows attackers to execute arbitrary code with elevated privileges on compromised systems.