CVE-2013-3956: High severity Novell client vulnerability
The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2 on Windows Vista and Windows Server 2008; and Novell Client 2 SP3 on Windows Server 2008 R2, Windows 7, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted 0x143B6B IOCTL call.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3956?
CVE-2013-3956 has a high severity rating due to its ability to allow local users to gain elevated privileges.
Which versions are affected by CVE-2013-3956?
CVE-2013-3956 affects Novell Client versions 4.91 SP5, 2 SP2, and 2 SP3 on various Windows operating systems.
How do I fix CVE-2013-3956?
To fix CVE-2013-3956, update the Novell Client software to a patched version that addresses the privilege escalation vulnerability.
What are the potential impacts of CVE-2013-3956?
The potential impacts of CVE-2013-3956 include unauthorized access to sensitive data and full system control by local attackers.
Is CVE-2013-3956 exploitable remotely?
CVE-2013-3956 is not remotely exploitable as it requires local access to the affected systems.