Vulnerabilities > CVE-2013-1339 - Resource Management Errors vulnerability in Microsoft products

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

The Print Spooler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly manage memory during deletion of printer connections, which allows remote authenticated users to execute arbitrary code via a crafted request, aka "Print Spooler Vulnerability."

Common Weakness Enumeration (CWE)

Msbulletin

bulletin_idMS13-050
bulletin_url
date2013-06-11T00:00:00
impactElevation of Privilege
knowledgebase_id2839894
knowledgebase_url
severityImportant
titleVulnerability in Windows Print Spooler Components Could Allow Elevation of Privilege

Nessus

NASL familyWindows : Microsoft Bulletins
NASL idSMB_NT_MS13-050.NASL
descriptionThe remote Windows host is potentially affected by a vulnerability that could allow elevation of privilege when an authenticated attacker deletes a printer connection. An attacker who is able to successfully exploit the vulnerability could run arbitrary code on a user
last seen2020-06-01
modified2020-06-02
plugin id66866
published2013-06-11
reporterThis script is Copyright (C) 2013-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/66866
titleMS13-050: Vulnerability in Windows Print Spooler Components Could Allow Elevation of Privilege (2839894)

Oval

accepted2013-07-22T04:01:30.753-04:00
classvulnerability
contributors
nameSecPod Team
organizationSecPod Technologies
definition_extensions
  • commentMicrosoft Windows Vista (32-bit) Service Pack 2 is installed
    ovaloval:org.mitre.oval:def:6124
  • commentMicrosoft Windows Vista x64 Edition Service Pack 2 is installed
    ovaloval:org.mitre.oval:def:5594
  • commentMicrosoft Windows Server 2008 (32-bit) Service Pack 2 is installed
    ovaloval:org.mitre.oval:def:5653
  • commentMicrosoft Windows Server 2008 x64 Edition Service Pack 2 is installed
    ovaloval:org.mitre.oval:def:6216
  • commentMicrosoft Windows Server 2008 Itanium-Based Edition Service Pack 2 is installed
    ovaloval:org.mitre.oval:def:6150
  • commentMicrosoft Windows 7 (32-bit) Service Pack 1 is installed
    ovaloval:org.mitre.oval:def:12292
  • commentMicrosoft Windows 7 x64 Service Pack 1 is installed
    ovaloval:org.mitre.oval:def:12627
  • commentMicrosoft Windows Server 2008 R2 x64 Service Pack 1 is installed
    ovaloval:org.mitre.oval:def:12567
  • commentMicrosoft Windows Server 2008 R2 Itanium-Based Edition Service Pack 1 is installed
    ovaloval:org.mitre.oval:def:12583
  • commentMicrosoft Windows 8 is installed
    ovaloval:org.mitre.oval:def:15732
  • commentMicrosoft Windows Server 2012 is installed
    ovaloval:org.mitre.oval:def:16359
descriptionThe Print Spooler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly manage memory during deletion of printer connections, which allows remote authenticated users to execute arbitrary code via a crafted request, aka "Print Spooler Vulnerability."
familywindows
idoval:org.mitre.oval:def:16837
statusaccepted
submitted2013-06-13T12:49:02
titleVulnerability in Windows Print Spooler Components Could Allow Elevation of Privilege - MS13-050
version73

Seebug

bulletinFamilyexploit
descriptionBUGTRAQ ID: 60407 CVE(CAN) ID: CVE-2013-1339 Microsoft Windows是微软公司推出的一系列操作系统。 打印机被删除时 Microsoft Windows 打印后台处理程序处理内存的方式中存在一个特权提升漏洞。当经过身份验证的攻击者删除打印机连接时,该漏洞可能允许特权提升。攻击者必须拥有有效的登录凭据并能登录才能利用此漏洞。 0 Microsoft Windows Windows Vista 0 Microsoft Windows Windows Server 2012 Microsoft Windows Server 2008 Microsoft Windows RT Microsoft Windows 8 Microsoft Windows 7 厂商补丁: Microsoft --------- Microsoft已经为此发布了一个安全公告(MS13-050)以及相应补丁: MS13-050:Vulnerability in Windows Print Spooler Components Could Allow Elevation of Privilege (2839894) 链接:http://technet.microsoft.com/security/bulletin/MS13-050
idSSV:60845
last seen2017-11-19
modified2013-06-17
published2013-06-17
reporterRoot
titleMicrosoft Windows Print Spooler Service本地权限提升漏洞(CVE-2013-1339)