CVE-2013-3660CISA KEV
Microsoft Win32k Privilege Escalation Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges.
- Product
- Win32k
- Added to KEV
- 28 Mar 2022
- Federal remediation due
- 18 Apr 2022
- Known ransomware use
- Not reported