MS13-062: Vulnerability in Remote Procedure Call Could Allow Elevation of Privilege (2849470)

This script is Copyright (C) 2013-2014 Tenable Network Security, Inc.


Synopsis :

The Windows install on the remote host is affected by a privilege
escalation vulnerability.

Description :

The remote host contains a flaw in the way that Windows handles
asynchronous RPC requests, which can lead to elevation of privileges.
An attacker could exploit this issue to run arbitrary code and take
complete control of an affected system.

See also :

http://technet.microsoft.com/en-us/security/Bulletin/MS13-062

Solution :

Microsoft has released a set of patches for Windows XP, 2003, Vista,
2008, 7, 2008 R2, 8, and 2012.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.7
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 69327 ()

Bugtraq ID: 61673

CVE ID: CVE-2013-3175