Executive brief
The EPATHOBJ::pprFlattenRec function in win32k.sys in the Microsoft Windows kernel-mode drivers fails to properly initialize a pointer for the next object in a list. Local attackers can exploit this by triggering excessive paged memory consumption and calling the FlattenPath function to obtain write access to the PATHRECORD chain, leading to elevation of privileges.
Affected products
- Microsoft Windows XP SP2, SP3
- Microsoft Windows Server 2003 SP2
- Microsoft Windows Vista SP2
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows 7 SP1
- Microsoft Windows 8
- Microsoft Windows Server 2012
Timeline
- 2013-05-17: disclosed: Initial public disclosure via social media and mailing lists.
- 2013-07-09: patched: Microsoft released security bulletin MS13-053 to address the vulnerability.
- 2022-03-28: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.