Vulnerabilities > CVE-2013-3136 - Resource Management Errors vulnerability in Microsoft products
Attack vector
LOCAL Attack complexity
MEDIUM Privileges required
SINGLE Confidentiality impact
COMPLETE Integrity impact
NONE Availability impact
NONE Summary
The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Kernel Information Disclosure Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 6 |
Common Weakness Enumeration (CWE)
Msbulletin
bulletin_id | MS13-048 |
bulletin_url | |
date | 2013-06-11T00:00:00 |
impact | Information Disclosure |
knowledgebase_id | 2839229 |
knowledgebase_url | |
severity | Important |
title | Vulnerability in Windows Kernel Could Allow Information Disclosure |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS13-048.NASL |
description | The remote host contains a flaw in the way the Windows kernel handles certain page fault system calls. Successful exploitation could allow disclosure of kernel memory, which could aid in further attacks. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 66864 |
published | 2013-06-11 |
reporter | This script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/66864 |
title | MS13-048: Vulnerability in Windows Kernel Could Allow Information Disclosure (2839229) |
code |
|
Oval
accepted | 2013-08-05T04:00:20.046-04:00 | ||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||
description | The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Kernel Information Disclosure Vulnerability." | ||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||
id | oval:org.mitre.oval:def:16847 | ||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||
submitted | 2013-06-13T17:15:43 | ||||||||||||||||||||||||
title | Kernel Information Disclosure Vulnerability - MS13-048 | ||||||||||||||||||||||||
version | 73 |
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 60357 CVE(CAN) ID: CVE-2013-3136 Microsoft Windows是微软公司推出的一系列操作系统。 如果 Windows 内核不正确地处理内存中的对象,则存在一个信息泄露漏洞。成功利用此漏洞的攻击者可能泄露内核地址中的信息。攻击者必须拥有有效的登录凭据并能本地登录才能利用此漏洞。 0 Microsoft Windows XP Microsoft Windows Vista Microsoft Windows Storage Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2003 Microsoft Windows 8 Microsoft Windows 7 厂商补丁: Microsoft --------- Microsoft已经为此发布了一个安全公告(ms13-048)以及相应补丁: ms13-048:Vulnerability in Windows Kernel Could Allow Information Disclosure (2839229) 链接:http://technet.microsoft.com/security/bulletin/ms13-048 |
id | SSV:60844 |
last seen | 2017-11-19 |
modified | 2013-06-17 |
published | 2013-06-17 |
reporter | Root |
title | Microsoft Windows Kernel本地信息泄露漏洞(CVE-2013-3136)(MS13-048) |