Junglewise Threat Intelligence

CVE-2013-3660: Microsoft Win32k Privilege Escalation Vulnerability

CVE-2013-3660 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-28

Technologies: Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows Server 2003, Microsoft Windows Server 2012, Microsoft Windows XP, Microsoft Win32K, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

The EPATHOBJ::pprFlattenRec function in win32k.sys in the Microsoft Windows kernel-mode drivers fails to properly initialize a pointer for the next object in a list. Local attackers can exploit this by triggering excessive paged memory consumption and calling the FlattenPath function to obtain write access to the PATHRECORD chain, leading to elevation of privileges.

Affected products

  • Microsoft Windows XP SP2, SP3
  • Microsoft Windows Server 2003 SP2
  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8
  • Microsoft Windows Server 2012

Timeline

  • 2013-05-17: disclosed: Initial public disclosure via social media and mailing lists.
  • 2013-07-09: patched: Microsoft released security bulletin MS13-053 to address the vulnerability.
  • 2022-03-28: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.

Related threats