Summary
This host is missing an important security update according to Microsoft Bulletin MS13-058.
Impact
Successful exploitation will allow remote attackers to execute arbitrary code in the security context of the LocalSystem account.
Impact Level: System
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/ms13-058
Insight
The flaw is due to an unspecified error within Windows Defender related to pathnames and can be exploited to execute arbitrary code with system privileges.
Affected
Windows Defender for
Microsoft Windows 7 x32/x64 Edition Service Pack 1 and prior Microsoft Windows Server 2008 R2 x64 Edition Service Pack 1 and prior
References
Severity
Classification
-
CVE CVE-2013-3154 -
CVSS Base Score: 6.9
AV:L/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Microsoft 'ISATAP' Component Spoofing Vulnerability (978338)
- Microsoft .NET Framework Security Bypass Vulnerability (2984625)
- Microsoft InfoPath HTML Sanitisation Component XSS Vulnerability (2821818)
- Microsoft SharePoint Multiple Privilege Elevation Vulnerabilities (2695502)
- Microsoft Windows DNS Server Denial of Service Vulnerability (2647170)