Executive brief
The NDProxy.sys driver in the Microsoft Windows kernel contains an improper input validation vulnerability. A local attacker can exploit this by using a crafted application to gain elevated privileges on the system.
Affected products
- Microsoft Windows XP SP2, SP3
- Microsoft Windows Server 2003 SP2
Timeline
- 2013-11-27: exploited: Exploitation in the wild reported by FireEye.
- 2013-11-27: disclosed: Microsoft Security Advisory 2914486 published.
- 2014-02-11: patched: Microsoft released security update MS14-002 to address the vulnerability.
- 2022-03-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.