CISA Known Exploited Vulnerability

CVE-2013-3660

Microsoft · Win32k

Microsoft Win32k Privilege Escalation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-119
Ransomware Unknown

CISA description

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges.

Required action

Apply updates per vendor instructions.