CVE-2013-3899: Input Validation
Published Dec 11, 2013
·Updated
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate addresses, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."
Affected Software
3 affected components
Microsoft Windows Server 2003=sp2
Microsoft Windows XP=sp3
Microsoft Windows XP=sp2
Event History
Dec 11, 2013
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3899?
CVE-2013-3899 is rated as critical due to its potential for local privilege escalation.
2
How do I fix CVE-2013-3899?
To fix CVE-2013-3899, apply the security updates provided by Microsoft for affected versions of Windows.
3
Who is affected by CVE-2013-3899?
CVE-2013-3899 affects users of Microsoft Windows XP SP2, SP3, and Windows Server 2003 SP2.
4
What type of vulnerability is CVE-2013-3899?
CVE-2013-3899 is a memory corruption vulnerability in the win32k.sys component of the Windows operating system.
5
Can CVE-2013-3899 be exploited remotely?
No, CVE-2013-3899 requires local access to the system to exploit the vulnerability.