Summary
This host is missing an important security update according to Microsoft Bulletin MS13-058.
Impact
Successful exploitation will allow remote attackers to execute arbitrary code in the security context of the LocalSystem account.
Impact Level: System
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/ms13-058
Insight
The flaw is due to an unspecified error within Windows Defender related to pathnames and can be exploited to execute arbitrary code with system privileges.
Affected
Windows Defender for
Microsoft Windows 7 x32/x64 Edition Service Pack 1 and prior Microsoft Windows Server 2008 R2 x64 Edition Service Pack 1 and prior
References
Severity
Classification
-
CVE CVE-2013-3154 -
CVSS Base Score: 6.9
AV:L/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Microsoft Windows Defender Privilege Elevation Vulnerability (2847927)
- Microsoft IIS FTP Connection Status Request Denial of Service Vulnerability
- Microsoft .NET Framework XML HMAC Truncation Vulnerability (981343)
- Flaw in SMB Signing Could Enable Group Policy to be Modified (329170)
- Microsoft Graphics Component Information Disclosure Vulnerability (3029944)