Vulnerabilities > CVE-2013-3862 - Resource Management Errors vulnerability in Microsoft Windows 7 and Windows Server 2008
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Double free vulnerability in Microsoft Windows 7 and Server 2008 R2 SP1 allows local users to gain privileges via a crafted service description that is not properly handled by services.exe in the Service Control Manager (SCM), aka "Service Control Manager Double Free Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 4 |
Common Weakness Enumeration (CWE)
Msbulletin
bulletin_id | MS13-077 |
bulletin_url | |
date | 2013-09-10T00:00:00 |
impact | Elevation of Privilege |
knowledgebase_id | 2872339 |
knowledgebase_url | |
severity | Important |
title | Vulnerability in Windows Service Control Manager Could Allow Elevation of Privilege |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS13-077.NASL |
description | The remote Windows host is potentially affected by a privilege escalation vulnerability in the Windows Service Control Manager. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 69836 |
published | 2013-09-11 |
reporter | This script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/69836 |
title | MS13-077: Vulnerability in Windows Service Control Manager Could Allow Elevation of Privilege (2872339) |
code |
|
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 62182 CVE(CAN) ID: CVE-2013-3862 Windows是一款由美国微软公司开发的窗口化操作系统 Windows 服务控制管理器 (SCM) 处理内存中对象的方式中存在一个特权提升漏洞。此漏洞源于处理注册表内的服务描述时,服务控制管理器 (services.exe) 存在重复释放错误。成功利用此漏洞的攻击者可执行任意代码,并可完全控制受影响的系统 0 Microsoft Windows Server 2008 Microsoft Windows 7 厂商补丁: Microsoft --------- Microsoft已经为此发布了一个安全公告(MS13-076)以及相应补丁: MS13-076:Vulnerabilities in Kernel-Mode Drivers Could Allow Elevation of Privilege (2876315) 链接:http://technet.microsoft.com/security/bulletin/MS13-076 |
id | SSV:61004 |
last seen | 2017-11-19 |
modified | 2013-09-13 |
published | 2013-09-13 |
reporter | Root |
title | Microsoft Windows Service Control Manager 本地权限提升漏洞(CVE-2013-3862)(MS13-077) |