Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2013-1271

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Microsoft Windows是美国微软(Microsoft)公司发布的一系列操作系统。 Microsoft Windows XP SP2以及SP3,Windows Server 2003 SP2,Windows Vista SP2,Windows Server 2008 SP2,R2以及R2 SP1,Windows 7 Gold以及SP1的内核模式驱动中的win32k.sys中存在竞争条件漏洞。本地攻击者可通过特制应用程序利用该漏洞进行提权,从而读取任意内核内存位置中的内容。

AI Predicted 7.8 Difficulty: Moderate EPSS 1.52% · P74

Possible ATT&CK Techniques 1 AI

T1055 · Process Injection
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2013-1271

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Microsoft Windows ‘win32k.sys’竞争条件漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Windows是美国微软(Microsoft)公司发布的一系列操作系统。 Microsoft Windows XP SP2以及SP3,Windows Server 2003 SP2,Windows Vista SP2,Windows Server 2008 SP2,R2以及R2 SP1,Windows 7 Gold以及SP1的内核模式驱动中的win32k.sys中存在竞争条件漏洞。本地攻击者可通过特制应用程序利用该漏洞进行提权,从而读取任意内核内存位置中的内容。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2013-1271

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2013-1271

请登录查看更多情报信息。

Vendor Advisories for CVE-2013-1271 (3)

Same Patch Batch · n/a · 2013-02-13 · 79 CVEs total

CVE-2013-1262 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1263 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1278 Microsoft Windows 内核竞争条件漏洞
CVE-2013-1265 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1266 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1264 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1261 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1260 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1259 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1258 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1267 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1268 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1269 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1270 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1272 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1273 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1274 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1275 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1276 Microsoft Windows ‘win32k.sys’竞争条件漏洞
CVE-2013-1277 Microsoft Windows ‘win32k.sys’竞争条件漏洞

Showing top 20 of 79 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2013-1271

No comments yet


Leave a comment