Executive Summary

Summary
Title Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (2813170)
Informations
Name MS13-031 First vendor Publication 2013-04-09
Vendor Microsoft Last vendor Modification 2013-04-24
Severity (Vendor) Important Revision 1.1

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:C/I:N/A:N)
Cvss Base Score 4.9 Attack Range Local
Cvss Impact Score 6.9 Attack Complexity Low
Cvss Expoit Score 3.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Revision Note: V1.1 (April 24, 2013): Corrected update replacement. This is an informational change only. There were no changes to the security update files or detection logic.

Summary: This security update resolves two privately reported vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to the system and runs a specially crafted application. An attacker must have valid logon credentials and be able to log on locally to exploit the vulnerability.

Original Source

Url : http://technet.microsoft.com/en-us/security/bulletin/ms13-031

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-362 Race Condition

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:16257
 
Oval ID: oval:org.mitre.oval:def:16257
Title: Kernel Race Condition Vulnerability - CVE-2013-1294 (MS13-031)
Description: Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2013-1294
Version: 7
Platform(s): Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows 8
Microsoft Windows Server 2012
Microsoft Windows Vista
Microsoft Windows 7
Product(s):
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:16455
 
Oval ID: oval:org.mitre.oval:def:16455
Title: Kernel Race Condition Vulnerability - CVE-2013-1284 (MS13-031)
Description: Race condition in the kernel in Microsoft Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2013-1284
Version: 3
Platform(s): Microsoft Windows 8
Microsoft Windows Server 2012
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 4
Os 2
Os 1
Os 1
Os 5
Os 1
Os 1
Os 2

Information Assurance Vulnerability Management (IAVM)

Date Description
2013-04-11 IAVM : 2013-A-0080 - Microsoft Windows Kernel Privilege Escalation Vulnerability
Severity : Category II - VMSKEY : V0037609

Nessus® Vulnerability Scanner

Date Description
2013-04-10 Name : The Windows kernel on the remote host is affected by multiple vulnerabilities.
File : smb_nt_ms13-031.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
Date Informations
2016-04-27 02:01:33
  • Multiple Updates
2014-02-17 11:47:37
  • Multiple Updates
2013-11-11 12:41:33
  • Multiple Updates
2013-10-11 13:30:48
  • Multiple Updates
2013-04-25 00:20:05
  • Multiple Updates
2013-04-25 00:17:07
  • Multiple Updates
2013-04-11 00:20:43
  • Multiple Updates
2013-04-10 13:20:15
  • Multiple Updates
2013-04-09 21:20:19
  • Multiple Updates
2013-04-09 21:15:44
  • First insertion