CVE-2013-5065

CVE Published 2013-11-28
Related CWE(s) CWE-20: Improper Input Validation
Related Vendor(s) microsoft
Related Product(s) windows_xp, windows_2003_server
Exploitation Reported (CISA KEV) 2022-03-03
CVSS 3 Base Score 7.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector LOCAL

NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References